{
  "day": "2026-09-25",
  "boundary": "UTC calendar day",
  "published_count": 681,
  "by_severity": {
    "CRITICAL": 22,
    "HIGH": 170,
    "MEDIUM": 155,
    "LOW": 25
  },
  "kev_count": 0,
  "exploit_reference_count": 0,
  "awaiting_enrichment_count": 309,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-19804",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0104,
      "epss_percentile": 0.62494,
      "kev": false,
      "kev_due_at": null,
      "vendor": "clavaque",
      "product": "s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions",
      "cwe": "CWE-94",
      "title": "s2Member <= 260814 - Unauthenticated Remote Code Execution via 'first_name' Parameter in PayPal Proxy Return",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19804"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-97730",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.01025,
      "epss_percentile": 0.62073,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netgate",
      "product": "pfSense Plus",
      "cwe": "CWE-24",
      "title": "In Netgate pfSense Plus before 26.07 and pfSense CE before 2.9.0, a Local File Inclusion (LFI) vulnerability in the Dashboard (index.php) widget sequence data handling allows an authenticated attacker to execute arbitrary PHP code. To exploit this, an attacker with privileges to modify Dashboard settings and write arbitrary files to the pfSense firewall system (e.g., /tmp/test.widget.php) can submit a crafted widget sequence value containing a path traversal payload (e.g., ../../../../../../../../../../../tmp/test). The Dashboard will subsequently read and execute the arbitrary PHP file as if it were a standard widget.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97730"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-13456",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00749,
      "epss_percentile": 0.52955,
      "kev": false,
      "kev_due_at": null,
      "vendor": "flippercode",
      "product": "WP Maps – Google Maps, OpenStreetMap, Mapbox, Store Locator with Search, Filters & Listings",
      "cwe": "CWE-98",
      "title": "WP Maps <= 4.9.8 - Authenticated (Subscriber+) Local File Inclusion via 'page' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13456"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-17602",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00557,
      "epss_percentile": 0.44087,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sslzen",
      "product": "SSL Zen — SSL Certificate Installer & HTTPS Redirects",
      "cwe": "CWE-22",
      "title": "SSL Zen <= 4.7.42 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'file_name' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17602"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-92106",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00538,
      "epss_percentile": 0.42926,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dashbitco",
      "product": "lazy_html",
      "cwe": "CWE-79",
      "title": "lazy_html serializes SVG and MathML style and script text unescaped, allowing mutation XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92106"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-14281",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00531,
      "epss_percentile": 0.4248,
      "kev": false,
      "kev_due_at": null,
      "vendor": "101gen",
      "product": "Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code",
      "cwe": "CWE-269",
      "title": "Automation Web Platform <= 4.8.6 - Unauthenticated Privilege Escalation via 'wawp_custom_fields' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14281"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-89426",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00475,
      "epss_percentile": 0.38499,
      "kev": false,
      "kev_due_at": null,
      "vendor": "knitpay",
      "product": "Knit Pay – Cashfree, Instamojo, Razorpay, PayPal and more",
      "cwe": "CWE-269",
      "title": "Knit Pay <= 9.6.1.0 - Authenticated (Subscriber+) Privilege Escalation via Gravity Forms Role Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89426"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-89406",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00394,
      "epss_percentile": 0.3087,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpchill",
      "product": "Modula Image Gallery – Photo Grid & Video Gallery",
      "cwe": "CWE-862",
      "title": "Modula Image Gallery <= 3.0.1 - Missing Authorization to Unauthenticated Private Gallery Image Disclosure via 'modula_gallery_id' and 'modula_image_id' Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89406"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-89055",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00385,
      "epss_percentile": 0.29793,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ivole",
      "product": "Customer Reviews for WooCommerce",
      "cwe": "CWE-862",
      "title": "Customer Reviews for WooCommerce <= 5.120.0 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion via 'items[][media]' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89055"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-93399",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0037,
      "epss_percentile": 0.28244,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ladela",
      "product": "Online Scheduling and Appointment Booking System – Bookly",
      "cwe": "CWE-639",
      "title": "Online Scheduling and Appointment Booking System <= 28.2 - Insecure Direct Object Reference to Unauthenticated Arbitrary Booking Token Disclosure and Deletion via 'order_id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93399"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-53493",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00356,
      "epss_percentile": 0.26672,
      "kev": false,
      "kev_due_at": null,
      "vendor": "containerd",
      "product": "containerd",
      "cwe": "CWE-400",
      "title": "Containerd has image-pull DoS via crafted OCI index graph amplification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53493"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-93901",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00346,
      "epss_percentile": 0.2542,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ihomefinder",
      "product": "Optima Express IDX",
      "cwe": "CWE-269",
      "title": "Optima Express IDX <= 8.7.5 - Unauthenticated Privilege Escalation to 'ihf_clear_cache' AJAX Action to Author Role Assignment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93901"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-13179",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00329,
      "epss_percentile": 0.23381,
      "kev": false,
      "kev_due_at": null,
      "vendor": "flippercode",
      "product": "WP Maps – Google Maps, OpenStreetMap, Mapbox, Store Locator with Search, Filters & Listings",
      "cwe": "CWE-79",
      "title": "WP Maps <= 4.9.8 - Authenticated (Subscriber+) Stored Cross-Site Scripting via shapes_values Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13179"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-92829",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00322,
      "epss_percentile": 0.22589,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pr-gateway",
      "product": "Blog2Social: Social Media Auto Post & Scheduler",
      "cwe": "CWE-862",
      "title": "Blog2Social: Social Media Auto Post & Scheduler <= 9.1.0 - Missing Authorization to Authenticated (Contributor+) Arbitrary Modification via Multiple AJAX Handlers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92829"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-97863",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0032,
      "epss_percentile": 0.22288,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp-modules",
      "cwe": "CWE-78",
      "title": "misp-modules: Shell Command Injection in MISP cisco_firesight_manager_ACL_rule_export Module via Unescaped Attribute Values",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97863"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-97818",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00317,
      "epss_percentile": 0.22065,
      "kev": false,
      "kev_due_at": null,
      "vendor": "phpipam",
      "product": "phpIPAM",
      "cwe": "CWE-863",
      "title": "phpIPAM through 1.8.3 has incorrect authorization for id==\"admins\" and id==\"all\" in api/controllers/User.php.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97818"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-92799",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00315,
      "epss_percentile": 0.21775,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ladela",
      "product": "Online Scheduling and Appointment Booking System – Bookly",
      "cwe": "CWE-285",
      "title": "Online Scheduling and Appointment Booking System <= 28.2 - Unauthenticated Authorization Bypass via PHP Type Juggling via 'verification_code' Parameter Type Juggling via json_data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92799"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-97647",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00311,
      "epss_percentile": 0.21357,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ningzichun",
      "product": "student-management-system",
      "cwe": "CWE-285",
      "title": "ningzichun student-management-system editLog.php authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97647"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-97646",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00302,
      "epss_percentile": 0.20501,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ningzichun",
      "product": "student-management-system",
      "cwe": "CWE-285",
      "title": "ningzichun student-management-system getStudent.php authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97646"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-12037",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00295,
      "epss_percentile": 0.19771,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gabelivan",
      "product": "Asset CleanUp: Page Speed Booster",
      "cwe": "CWE-918",
      "title": "Asset CleanUp: Page Speed Booster <= 1.4.0.5 - Authenticated (Administrator+) Server-Side Request Forgery via 'page_url' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12037"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-17577",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00274,
      "epss_percentile": 0.17632,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sslzen",
      "product": "SSL Zen — SSL Certificate Installer & HTTPS Redirects",
      "cwe": "CWE-79",
      "title": "SSL Zen <= 4.7.42 - Reflected Cross-Site Scripting via 'uri' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17577"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-88996",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00274,
      "epss_percentile": 0.17632,
      "kev": false,
      "kev_due_at": null,
      "vendor": "smub",
      "product": "WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More",
      "cwe": "CWE-79",
      "title": "WPForms <= 2.0.2 - Reflected Cross-Site Scripting via 'page_title' POST Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88996"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-92713",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00273,
      "epss_percentile": 0.17578,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpchill",
      "product": "Modula Image Gallery – Photo Grid & Video Gallery",
      "cwe": "CWE-862",
      "title": "Modula Image Gallery <= 3.0.2 - Missing Authorization to Authenticated (Author+) Arbitrary File Deletion (Non-PHP) via 'file' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92713"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-84280",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00273,
      "epss_percentile": 0.17612,
      "kev": false,
      "kev_due_at": null,
      "vendor": "radykal",
      "product": "Fancy Product Designer",
      "cwe": "CWE-79",
      "title": "Fancy Product Designer <= 6.5.2 - Unauthenticated Stored Cross-Site Scripting via Shortcode Order 'elements[].title' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84280"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-97650",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00273,
      "epss_percentile": 0.17555,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ningzichun",
      "product": "student-management-system",
      "cwe": "CWE-79",
      "title": "ningzichun student-management-system addLog.php echo cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97650"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-95864",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00272,
      "epss_percentile": 0.1744,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themifyme",
      "product": "Themify Builder",
      "cwe": "CWE-79",
      "title": "Themify Builder <= 7.8.1 - Unauthenticated Stored Cross-Site Scripting via 'css[fonts]' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95864"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-93899",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.16963,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wordplus",
      "product": "Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots",
      "cwe": "CWE-89",
      "title": "Better Messages <= 3.0.4 - Authenticated (Subscriber+) SQL Injection via 'group_id' Message Meta Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93899"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-97737",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00266,
      "epss_percentile": 0.1674,
      "kev": false,
      "kev_due_at": null,
      "vendor": "muety",
      "product": "Wakapi",
      "cwe": "CWE-843",
      "title": "In Wakapi before 2.17.6, the user caching service allows a lookup to be resolved in an unintended lookup context, leading to account takeover.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97737"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-95866",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00256,
      "epss_percentile": 0.1534,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cozmoslabs",
      "product": "User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor",
      "cwe": "CWE-79",
      "title": "User Profile Builder <= 4.0.2 - Unauthenticated Stored Cross-Site Scripting via Avatar Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95866"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-97735",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00254,
      "epss_percentile": 0.15097,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ITFlow",
      "product": "ITFlow",
      "cwe": "CWE-79",
      "title": "ITFlow before 26.08 allows SVG attachments in the ticket email parser (cron/ticket_email_parser.php) for email messages that may arrive over SMTP from arbitrary senders.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97735"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-97724",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00253,
      "epss_percentile": 0.14949,
      "kev": false,
      "kev_due_at": null,
      "vendor": "swmansion",
      "product": "React Native Reanimated",
      "cwe": "CWE-1321",
      "title": "A prototype pollution vulnerability in Software Mansion React Native Worklets before 0.12.2 allows an attacker-controlled object containing a __proto__ property to modify the prototype of an object created during serialization in clonePlainJSObject in packages/react-native-worklets/src/memory/serializable.native.ts. When affected data is subsequently processed by React Native Worklets, the malformed serialized object can cause the React Native application to crash. This can result in a remotely triggered denial of service in applications that pass attacker-controlled data through the affected serialization path. In applications where the attacker-controlled data is persisted, the denial of service may persist across application restarts or repeated attempts to access the affected content.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97724"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-95811",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00252,
      "epss_percentile": 0.14898,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "Lemonldap-NG-Handler",
      "cwe": "CWE-180",
      "title": "Lemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow an equivalent spelling of a path to bypass the locationRules that restrict it",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95811"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-83591",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00247,
      "epss_percentile": 0.14224,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mohammed_kaludi",
      "product": "AMP for WP – Accelerated Mobile Pages",
      "cwe": "CWE-79",
      "title": "AMP for WP <= 1.1.16 - Unauthenticated Stored Cross-Site Scripting via Comment Content Regex Transformation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83591"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-93303",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00247,
      "epss_percentile": 0.14223,
      "kev": false,
      "kev_due_at": null,
      "vendor": "htplugins",
      "product": "HT Contact Form – Drag & Drop Form Builder for WordPress",
      "cwe": "CWE-79",
      "title": "HT Contact Form <= 2.10.1 - Unauthenticated Stored DOM-Based Cross-Site Scripting via 'form_data' Rich Text Field via Draft Save/Resume",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93303"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-93654",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00241,
      "epss_percentile": 0.13603,
      "kev": false,
      "kev_due_at": null,
      "vendor": "codename065",
      "product": "Premium Packages – Sell Digital Products Securely",
      "cwe": "CWE-79",
      "title": "Premium Packages <= 7.2.1 - Unauthenticated Stored Cross-Site Scripting via 'cart_items[][product_name]' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93654"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-94573",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00241,
      "epss_percentile": 0.13602,
      "kev": false,
      "kev_due_at": null,
      "vendor": "addonsorg",
      "product": "Repeater Fields for Elementor Forms",
      "cwe": "CWE-79",
      "title": "Repeater Fields for Elementor Forms <= 2.2.7 - Unauthenticated Stored Cross-Site Scripting via Repeater Field Value",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94573"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-96039",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00241,
      "epss_percentile": 0.13602,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bookingalgorithms",
      "product": "BA Book Everything",
      "cwe": "CWE-79",
      "title": "BA Book Everything <= 1.8.27 - Unauthenticated Stored Cross-Site Scripting via first_name Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96039"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-96568",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00241,
      "epss_percentile": 0.13602,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jetmonsters",
      "product": "Restaurant Menu and Food Ordering",
      "cwe": "CWE-79",
      "title": "Restaurant Menu and Food Ordering <= 2.4.14 - Unauthenticated Stored Cross-Site Scripting via 'phone_number' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96568"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-96752",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00241,
      "epss_percentile": 0.13602,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bmarshall511",
      "product": "Zero Spam for WordPress",
      "cwe": "CWE-79",
      "title": "Zero Spam for WordPress <= 5.7.10 - Unauthenticated Stored Cross-Site Scripting via Nested POST Array Keys via Contact Form 7 Integration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96752"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-96448",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00237,
      "epss_percentile": 0.1313,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-285",
      "title": "Keycloak-services: keycloak-services: fgap v2 composite-blind role mapping allows privilege escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96448"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-97721",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00236,
      "epss_percentile": 0.13065,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sanluan",
      "product": "PublicCMS",
      "cwe": "CWE-285",
      "title": "Sanluan PublicCMS exportExcel/exportData SysUserAdminController.java CmsContentAdminController authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97721"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-19775",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00234,
      "epss_percentile": 0.12778,
      "kev": false,
      "kev_due_at": null,
      "vendor": "allterraindeveloper",
      "product": "OpenStation: Desktop Windows, Dock & Virtual Desktops for WP Admin",
      "cwe": "CWE-862",
      "title": "OpenStation <= 1.1.7 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via AI Copilot Search Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19775"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-6082",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.12358,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Novadigits technologies",
      "product": "StockAgile",
      "cwe": "CWE-79",
      "title": "Stored Cross-Site Scripting in StockAgile by Novadigits technologies",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6082"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-6083",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.12359,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Novadigits technologies",
      "product": "StockAgile",
      "cwe": "CWE-79",
      "title": "Stored Cross-Site Scripting in StockAgile by Novadigits technologies",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6083"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-6084",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.12357,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Novadigits technologies",
      "product": "StockAgile",
      "cwe": "CWE-79",
      "title": "Stored Cross-Site Scripting in StockAgile by Novadigits technologies",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6084"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-6085",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.12357,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Novadigits technologies",
      "product": "StockAgile",
      "cwe": "CWE-79",
      "title": "Stored Cross-Site Scripting in StockAgile by Novadigits technologies",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6085"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-6086",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.12358,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Novadigits technologies",
      "product": "StockAgile",
      "cwe": "CWE-79",
      "title": "Stored Cross-Site Scripting in StockAgile by Novadigits technologies",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6086"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-6087",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.12357,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Novadigits technologies",
      "product": "StockAgile",
      "cwe": "CWE-79",
      "title": "Stored Cross-Site Scripting in StockAgile by Novadigits technologies",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6087"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-6088",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.12358,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Novadigits technologies",
      "product": "StockAgile",
      "cwe": "CWE-79",
      "title": "Stored Cross-Site Scripting in StockAgile by Novadigits technologies",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6088"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-97649",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00227,
      "epss_percentile": 0.12011,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ningzichun",
      "product": "student-management-system",
      "cwe": "CWE-1392",
      "title": "ningzichun student-management-system example_lite.sql default credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97649"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-97764",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00226,
      "epss_percentile": 0.11946,
      "kev": false,
      "kev_due_at": null,
      "vendor": "allauth",
      "product": "django-allauth",
      "cwe": "CWE-180",
      "title": "django-allauth before 65.19.4 does not have the expected limits on failed login attempts because, in some common configurations, an attacker can leverage the handling of diacritics (e.g., accents) for a higher effective limit.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97764"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-92289",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00222,
      "epss_percentile": 0.11433,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "Lemonldap-NG-Portal",
      "cwe": "CWE-1390",
      "title": "Lemonldap::NG::Portal versions from 2.23.0 before 2.23.4 for Perl allow a PKCE bypass for public Relying Parties in \"PKCE or secret\" mode because checkEndPointAuthenticationCredentials does not verify the client secret",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92289"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-93897",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00216,
      "epss_percentile": 0.107,
      "kev": false,
      "kev_due_at": null,
      "vendor": "paoltaia",
      "product": "GeoDirectory – WP Business Directory Plugin and Classified Listings Directory",
      "cwe": "CWE-79",
      "title": "GeoDirectory <= 2.8.181 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Text-type Custom Field (e.g., 'phone')",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93897"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-92212",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00215,
      "epss_percentile": 0.10632,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jetmonsters",
      "product": "JetFormBuilder — Dynamic Blocks Form Builder",
      "cwe": "CWE-79",
      "title": "JetFormBuilder <= 3.6.5.3 - Reflected Cross-Site Scripting via 'jfb_xss' (URL Query Variable) Parameter via Calculated Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92212"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-92288",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00211,
      "epss_percentile": 0.10195,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "Lemonldap-NG-Portal",
      "cwe": "CWE-1390",
      "title": "Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow unauthenticated OAuth2 token introspection because checkEndPointAuthenticationCredentials does not verify the client secret of a public Relying Party",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92288"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-97723",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00209,
      "epss_percentile": 0.09903,
      "kev": false,
      "kev_due_at": null,
      "vendor": "madpsy",
      "product": "ka9q_ubersdr",
      "cwe": "CWE-79",
      "title": "madpsy ka9q_ubersdr before 0.1.58 has a stored cross-site scripting (XSS) vulnerability in the chat message rendering functionality. User-controlled URLs in chat messages were insufficiently neutralized before being converted into HTML links. Quotation characters could break out of the generated href attribute and introduce attacker-controlled HTML attributes, allowing arbitrary JavaScript to execute in the browser of another user when the stored chat message was rendered. No click on the malicious link was required.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97723"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-97736",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00208,
      "epss_percentile": 0.09708,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tinyauth",
      "product": "tinyauth",
      "cwe": "CWE-777",
      "title": "tinyauth before 5.1.3 allows rule bypass by appending an allowed route string. This is caused by an unanchored regular expression.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97736"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-84281",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00206,
      "epss_percentile": 0.09477,
      "kev": false,
      "kev_due_at": null,
      "vendor": "radykal",
      "product": "Fancy Product Designer",
      "cwe": "CWE-79",
      "title": "Fancy Product Designer <= 6.5.2 - Unauthenticated Stored Cross-Site Scripting via 'productTitle' in '_fpd_data' Order Item Meta",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84281"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-93656",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.08859,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cozmoslabs",
      "product": "User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor",
      "cwe": "CWE-79",
      "title": "User Profile Builder <= 4.0.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Avatar Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93656"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-93747",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.08858,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tomdever",
      "product": "wpForo Forum",
      "cwe": "CWE-79",
      "title": "wpForo Forum <= 3.1.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'telegram' Profile Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93747"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-96766",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.08858,
      "kev": false,
      "kev_due_at": null,
      "vendor": "paoltaia",
      "product": "GeoDirectory – WP Business Directory Plugin and Classified Listings Directory",
      "cwe": "CWE-79",
      "title": "GeoDirectory <= 2.8.183 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'business_hours' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96766"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-93477",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.08364,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash",
      "cwe": "CWE-915",
      "title": "Private action arguments can be set by user input on the bulk destroy and bulk update paths in Ash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93477"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-92609",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00195,
      "epss_percentile": 0.08173,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Qpid Broker-J",
      "cwe": "CWE-384",
      "title": "Apache Qpid Broker-J: Missing HTTP-session renewal after successful authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92609"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-92550",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00193,
      "epss_percentile": 0.07986,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Qpid Broker-J",
      "cwe": "CWE-789",
      "title": "Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-8/0-9/0-9-1 decoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92550"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-92560",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00193,
      "epss_percentile": 0.07986,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Qpid Broker-J",
      "cwe": "CWE-770",
      "title": "Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-10 decoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92560"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-92746",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.07994,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jegstudio",
      "product": "Gutenverse – WordPress Blocks, Page Builder & Site Editor",
      "cwe": "CWE-79",
      "title": "Gutenverse <= 4.0.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Comment Block 'suffixMain' Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92746"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-94376",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.07993,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wordplus",
      "product": "Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots",
      "cwe": "CWE-79",
      "title": "Better Messages <= 3.0.4 - Authenticated (Subscriber+) Stored DOM-Based Cross-Site Scripting via User Display Name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94376"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-92564",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00193,
      "epss_percentile": 0.07986,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Qpid Broker-J",
      "cwe": "CWE-674",
      "title": "Apache Qpid Broker-J: Unbounded type nesting can lead to stack overflow pre-authentication in AMQP 0-8/0-9/0-9-1 field-table processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92564"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-85417",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00191,
      "epss_percentile": 0.07765,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Brocade",
      "product": "SANnav",
      "cwe": "CWE-532",
      "title": "Incomplete property masking in the SANnav logging subsystem",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85417"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-84279",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0019,
      "epss_percentile": 0.07702,
      "kev": false,
      "kev_due_at": null,
      "vendor": "radykal",
      "product": "Fancy Product Designer",
      "cwe": "CWE-79",
      "title": "Fancy Product Designer <= 6.5.2 - Unauthenticated Stored Cross-Site Scripting via 'output_format' Parameter via Pro Export Print Job",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84279"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-86837",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.06888,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Bookly",
      "cwe": "CWE-639",
      "title": "Bookly < 28.3 - Unauthenticated Customer PII Update via Verification Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86837"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-97648",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00162,
      "epss_percentile": 0.04675,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ningzichun",
      "product": "student-management-system",
      "cwe": "CWE-352",
      "title": "ningzichun student-management-system cross-site request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97648"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-80514",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0016,
      "epss_percentile": 0.04396,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "wpForo Forum",
      "cwe": "CWE-348",
      "title": "wpForo Forum 3.0.0 - 3.1.5 - Unauthenticated AI Credit Exhaustion via IP Rate Limit Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80514"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-92608",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00159,
      "epss_percentile": 0.04271,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Qpid Broker-J",
      "cwe": "CWE-248",
      "title": "Apache Qpid Broker-J: Incomplete property conversion handling from AMQP 1.0 to AMQP 0-10",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92608"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-92573",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.04272,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Qpid Broker-J",
      "cwe": "CWE-409",
      "title": "Apache Qpid Broker-J: Uncontrolled resource consumption during AMQP delivery decompression, message conversion and HTTP management JSON rendering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92573"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-78394",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00157,
      "epss_percentile": 0.0413,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Link Library",
      "cwe": "CWE-22",
      "title": "Link Library < 7.9.6 - Contributor+ Path Traversal via 'filepath' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78394"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2025-14814",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.04026,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wipeoutmedia",
      "product": "CSS & JavaScript Toolbox",
      "cwe": "CWE-79",
      "title": "CSS & JavaScript Toolbox <= 12.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via cjtoolbox Shortcode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-14814"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-97731",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00154,
      "epss_percentile": 0.0384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MinIO",
      "product": "MinIO",
      "cwe": "CWE-347",
      "title": "MinIO through 7aac2a2 does not verify that every x-amz-* header present on a request also appears in the client-supplied X-Amz-SignedHeaders list. extractSignedHeaders() in cmd/signature-v4-utils.go iterates only the claimed list and never enumerates the headers that actually arrived, and thus a header that arrives unsigned is neither hashed into the canonical request nor rejected. Because cmd/api-router.go dispatches CopyObject on the presence of x-amz-copy-source alone, the holder of a presigned PUT URL scoped to a single object can add that header to the unmodified URL and cause a server-side copy, executed as the signer, of any object the signing key can read. A grant to write one object becomes a read of every bucket that key can reach. Amazon S3 rejects the equivalent request with HTTP 403 AccessDenied. The minio/minio GitHub repository was archived in April 2026; pgsty/silo before 1233254 is also affected.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97731"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-78393",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.03646,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Link Library",
      "cwe": "CWE-79",
      "title": "Link Library < 7.9.6 - Reflected XSS via 'link_tags' and 'link_price' Sort and Breadcrumb Links",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78393"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-75553",
      "cvss_base": 2.4,
      "cvss_severity": "LOW",
      "epss_score": 0.00142,
      "epss_percentile": 0.02842,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tohoku Electric Power Company, Incorporated",
      "product": "Tohoku Electric Power \"Yorisou e Net\" Android App",
      "cwe": "CWE-321",
      "title": "Smartphone application Tohoku Electric Power \"Yorisou e Net\" uses a hard-coded cryptographic key, which may allow an attacker to retrieve a hard-coded cryptographic key from the affected product.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75553"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-97846",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00135,
      "epss_percentile": 0.02413,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-287",
      "title": "Keycloak-services: keycloak-services: standard token exchange v2 bypasses mtls holder-of-key binding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97846"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-78397",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.02267,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Link Library",
      "cwe": "CWE-918",
      "title": "Link Library < 7.9.6 - Unauthenticated SSRF via Reciprocal Link Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78397"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-62062",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0013,
      "epss_percentile": 0.02181,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elementor",
      "product": "Elementor Website Builder",
      "cwe": "CWE-352",
      "title": "WordPress Elementor Website Builder plugin <= 4.3.1 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62062"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-88848",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00119,
      "epss_percentile": 0.01589,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MasterStudy LMS",
      "cwe": "CWE-863",
      "title": "MasterStudy LMS 1.9 - < 3.7.50 - Subscriber+ Membership Plan Quota and Category Restriction Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88848"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-97732",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00056,
      "epss_percentile": 0.00003,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IRONMACE",
      "product": "Ironshield",
      "cwe": "CWE-347",
      "title": "IRONMACE Ironshield 1.0.0.167 has a tvk.sys kernel-mode driver that authenticates client executables by checking for expected publisher and root-certificate strings in WIN_CERTIFICATE data (\"IRONMACE Co., Ltd.\" and \"DigiCert Trusted Root G4\") instead of parsing and validating the PKCS signature data. As a result, a local unprivileged attacker may bypass this via crafted certificate data and obtain access to privileged IOCTL functionality.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97732"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-100382",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wikimedia Foundation",
      "product": "Mediawiki - ExternalData Extension",
      "cwe": "CWE-78",
      "title": "Unauthenticated remote code execution through wikitext in ExternalData",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100382"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-92161",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FriendsOfFlarum",
      "product": "oauth",
      "cwe": "CWE-345",
      "title": "FriendsOfFlarum OAuth: Unauthenticated account takeover via unverified email trust in Discord OAuth provider",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92161"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-93643",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zimbra",
      "product": "Zimbra Collaboration Suite (ZCS)",
      "cwe": "CWE-22",
      "title": "Zimbra Collaboration Suite OnlyOffice Integration Path Traversal Leading to Remote Code Execution via Unauthenticated /downloadas Request",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93643"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-100075",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100075"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-48482",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "glpi-project",
      "product": "glpi",
      "cwe": "CWE-22",
      "title": "GLPI: RCE via Form import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48482"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-93641",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zimbra",
      "product": "Zimbra Collaboration Suite (ZCS)",
      "cwe": "CWE-79",
      "title": "Zimbra Collaboration Suite Classic Web Client Stored Cross-Site Scripting via Forged Share Invitation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93641"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-93642",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zimbra",
      "product": "Zimbra Collaboration Suite (ZCS)",
      "cwe": "CWE-79",
      "title": "Zimbra Collaboration Suite Modern Web Client Stored Cross-Site Scripting via Forged Share Invitation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93642"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-93647",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zimbra",
      "product": "Zimbra Collaboration Suite (ZCS)",
      "cwe": "CWE-79",
      "title": "Zimbra Collaboration Suite Classic Web Client Stored Cross-Site Scripting via Crafted Calendar COUNTER Message From Address",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93647"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-95832",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kovid Goyal",
      "product": "kitty",
      "cwe": "CWE-74",
      "title": "Reflected unknown field names in the kitty colour control escape code allow command execution in the user's shell",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95832"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-97063",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yzcheng90",
      "product": "X-SpringBoot",
      "cwe": "CWE-287",
      "title": "X-SpringBoot through 6.0 Authentication Bypass via Login Code",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97063"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-97064",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yzcheng90",
      "product": "X-SpringBoot",
      "cwe": "CWE-1392",
      "title": "X-SpringBoot through 6.0 Authentication Bypass via Static Master Code",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97064"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-100389",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GestSup",
      "product": "GestSup",
      "cwe": "CWE-434",
      "title": "GestSup before 3.2.61 Remote Code Execution via IMAP Attachment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100389"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-39353",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "InvoicePlane",
      "product": "InvoicePlane",
      "cwe": "CWE-98",
      "title": "InvoicePlane: Remote Code Execution via Writable Templates Directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39353"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-42322",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Piwigo",
      "product": "Piwigo",
      "cwe": "CWE-434",
      "title": "Piwigo: Authenticated RCE via File Upload in Logo Upload Feature",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42322"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-62262",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Piwigo",
      "product": "Piwigo",
      "cwe": "CWE-89",
      "title": "Piwigo: Unauthenticated SQL injection in `pwg.images.filteredSearch.create`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62262"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-84458",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zammad",
      "product": "zammad",
      "cwe": "CWE-287",
      "title": "Zammad: Account takeover via unverified email matching during SSO auto-link",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84458"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-100390",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tobychui",
      "product": "zoraxy",
      "cwe": "CWE-290",
      "title": "Zoraxy 3.2.3 through 3.3.4 Client IP Spoofing via X-Forwarded-For IPv6",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100390"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2025-51457",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-77",
      "title": "D-Link DAP-2610 up to 2.06B08r099 contains an authenticated command injection vulnerability within the web interface at the /index.xgi endpoint. An attacker with authenticated access can exploit some parameters to execute arbitrary system commands.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-51457"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-61525",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zammad",
      "product": "zammad",
      "cwe": "CWE-22",
      "title": "Zammad: Arbitrary File Deletion via Unvalidated Session Identifier in Long Polling Controller",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61525"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-85542",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-78",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85542"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-93834",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-416",
      "title": "Qemu-kvm: 9pfs: use-after-free race in tlcreate/twalk allows vm guest escape",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93834"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-94445",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "golang.org/x/playground",
      "product": "golang.org/x/playground",
      "cwe": "CWE-20",
      "title": "Malicious user input may lead to RCE in golang.org/x/playground",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94445"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-96795",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "horilla",
      "product": "horilla-hr",
      "cwe": "CWE-94",
      "title": "Horilla: Authenticated RCE in Horilla List-View Export",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96795"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-96812",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "gVisor",
      "cwe": "CWE-269",
      "title": "Host Root Sandbox Escape in gVisor via Character Device Passthrough and CUSE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96812"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-97527",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: qla2xxx: Serialize NVMe unsol ctx list with a per-fcport lock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97527"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-97528",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: qla2xxx: Unlink NVMe unsol ctx before freeing on LS reject error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97528"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-97555",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: client: fix heap overflow in DACL owner/group rewrite",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97555"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-97957",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: hinic: fix mailbox segment buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97957"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-98115",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ksmbd: safely drain sessions during logoff",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98115"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-100391",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mhdzumair",
      "product": "mediaflow-proxy",
      "cwe": "CWE-918",
      "title": "MediaFlow Proxy through 2.4.9 Server-Side Request Forgery via Incomplete Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100391"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-56725",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zammad",
      "product": "zammad",
      "cwe": "CWE-306",
      "title": "Zammad: Denial of Service via OTRS Import Controller",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56725"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-56733",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zammad",
      "product": "zammad",
      "cwe": "CWE-269",
      "title": "Zammad: Incorrect Authorization and Improper Privilege Management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56733"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-89032",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BerriAI",
      "product": "litellm",
      "cwe": "CWE-863",
      "title": "BerriAI LiteLLM < 1.101.0-rc.1 Tenant Isolation Bypass via Semantic Cache Layer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89032"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-84462",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zammad",
      "product": "zammad",
      "cwe": "CWE-20",
      "title": "Zammad: AI Agent template sanitizer bypass leads to remote code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84462"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-97060",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yzcheng90",
      "product": "X-SpringBoot",
      "cwe": "CWE-639",
      "title": "X-SpringBoot through 6.0 Authorization Bypass via User Management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97060"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-100372",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MacWarrior",
      "product": "clipbucket-v5",
      "cwe": "CWE-22",
      "title": "ClipBucket v5 before 5.5.3-#197 Path Traversal via template_editor.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100372"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-47679",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "glpi-project",
      "product": "glpi",
      "cwe": "CWE-22",
      "title": "GLPI: arbitrary file deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47679"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-55214",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "glpi-project",
      "product": "glpi",
      "cwe": "CWE-116",
      "title": "GLPI: Stored XSS in suppliers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55214"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-71483",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "horilla",
      "product": "horilla-hr",
      "cwe": "CWE-79",
      "title": "Horilla: Reflected Cross-Site Scripting (XSS) in Employee Filter View",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71483"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-100172",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ail project",
      "product": "ail framework",
      "cwe": "CWE-79",
      "title": "Stored XSS in AIL Framework extracted-match popovers via unescaped dynamic values in HTML-enabled data-content attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100172"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-100176",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ail project",
      "product": "ail framework",
      "cwe": "CWE-79",
      "title": "Stored Cross-Site Scripting (XSS) in AIL Framework Username Timeline Tooltip",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100176"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-56731",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zammad",
      "product": "zammad",
      "cwe": "CWE-79",
      "title": "Zammad: Cross-Site Scripting in Ticket Notifications",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56731"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-97898",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "akia",
      "product": "akia",
      "cwe": "CWE-639",
      "title": "Broken authorization in Akia keyless entry lets an authenticated guest unlock other rooms",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97898"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-100248",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rattadan",
      "product": "Cosmowarp Contract",
      "cwe": "CWE-1025",
      "title": "The Rattadan Cosmowarp smart contract before 56c6147 can have a comparison to an unintended value of current_admin.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100248"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-100368",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "alastairlundy",
      "product": "CliInvoke.Specializations",
      "cwe": "CWE-78",
      "title": "CliInvoke.Specializations: Command injection in PowerShell and Cmd shell wrappers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100368"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-100369",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "alastairlundy",
      "product": "CliInvoke",
      "cwe": "CWE-88",
      "title": "CliInvoke: Argument Injection in Extensibility Runner Factory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100369"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-100501",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pawelmalak",
      "product": "flame",
      "cwe": "CWE-307",
      "title": "Flame through 2.4.0 Brute-Force Attack via Login Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100501"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-67236",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-312",
      "title": "RabbitMQ: Plaintext username:password stored in an insecure cookie after successful POST /login",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67236"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-67409",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-252",
      "title": "RabbitMQ: JWKS Fetch Ignores HTTP Response Status Code - Signing Key Destruction Causes Authentication DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67409"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-67410",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-200",
      "title": "RabbitMQ: OAuth2 Client Secret Exposed via Unauthenticated JavaScript Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67410"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-97525",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "x86/mm/pat: Allocate split page tables as kernel page tables",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97525"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-44642",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Piwigo",
      "product": "Piwigo",
      "cwe": "CWE-89",
      "title": "Piwigo: SQL injection in upgrade authentication allows unauthenticated upgrade authorization bypass (PHP 8+)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44642"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-51773",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-918",
      "title": "An issue in the VMware datastore driver of OpenStack glance_store. When an authenticated attacker provides a maliciously crafted image location URI pointing to an external server, the _retry_request function fails to validate the destination host before attaching sensitive authentication headers.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51773"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-97570",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bnxt_en: Bound SW TPA IDs to prevent crashes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97570"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-97573",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bnxt_en: Handle buffer allocation failure in bnxt_rx_ring_reset()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97573"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-97875",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rojo-rbx",
      "product": "rojo",
      "cwe": "CWE-350",
      "title": "DNS rebinding vulnerability in rojo serve HTTP API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97875"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-98069",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/rds: acquire the fastpath locks in rds_conn_shutdown()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98069"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-98070",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/rds: acquire RDS_IN_XMIT in rds_tcp_reset_callbacks()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98070"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-98130",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "sctp: fix a TOCTOU race in SCTP_CMD_TIMER_START",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98130"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-79153",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-269",
      "title": "Seclore FileSecure Desktop Client before 3.25.1.0 contains improper access control vulnerability in the kernel-mode driver component that allows an authenticated local user to gain elevated privileges to NT AUTHORITY\\SYSTEM on affected systems.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79153"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-91837",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNOME",
      "product": "NetworkManager-iodine",
      "cwe": "CWE-78",
      "title": "Networkmanager-iodine: networkmanager-iodine: local privilege escalation to root via nameserver option injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91837"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-91838",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNOME",
      "product": "NetworkManager-sstp",
      "cwe": "CWE-78",
      "title": "Networkmanager-sstp: networkmanager-sstp: local privilege escalation to root via shell injection in vpn profile fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91838"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-91839",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNOME",
      "product": "NetworkManager-fortisslvpn",
      "cwe": "CWE-93",
      "title": "Networkmanager-fortisslvpn: networkmanager-fortisslvpn: local privilege escalation to root via crlf injection in vpn profile credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91839"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-91840",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNOME",
      "product": "NetworkManager-vpnc",
      "cwe": "CWE-93",
      "title": "Networkmanager-vpnc: networkmanager-vpnc: local privilege escalation to root via newline injection in vpn username",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91840"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-91841",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNOME",
      "product": "NetworkManager-vpnc",
      "cwe": "CWE-93",
      "title": "Networkmanager-vpnc: networkmanager-vpnc: incomplete fix for cve-2018-10900 allows root privilege escalation via ca-file path newline injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91841"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-97548",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfs: fix the rtrmap and rtrefcount _maxlevels_ondisk functions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97548"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-97575",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: v4l2-ctrls: validate AV1 tile counts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97575"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-97576",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: v4l2-ctrls: validate HEVC tile counts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97576"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-97577",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: verisilicon: rockchip: reject AV1 frames exceeding the tile capacity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97577"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-97578",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: verisilicon: rockchip: guard VPU981 AV1 divisor and tile buffer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97578"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-97579",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: mediatek: vcodec: bound AV1 tile-start copy to the array capacity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97579"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-97580",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: rkvdec: bound HEVC tile loops and PPS id to the array capacity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97580"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-97584",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "afs: Fix incorrect free in candidate cleanup in afs_lookup_server()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97584"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-97594",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "landlock: Fix use-after-free of the source's parent directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97594"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-97602",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "inet: frags: invalidate queues before flushing them",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97602"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-97611",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: openvswitch: fix use-after-free of the flow table mask array",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97611"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-97612",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: mpls: clear inner_protocol when the last label is popped",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97612"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-97903",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "exit: hold a reference to thread_pid across proc_flush_pid",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97903"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-97910",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ASoC: sprd: validate compress buffer sizes against fixed allocations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97910"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-97911",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "accel: ethosu: Ensure SRAM region size matches job",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97911"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-97937",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ftrace: fork: Initialize function graph state before copy_exec_state()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97937"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-97940",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipv6: fix fib6 walker UAF on seq stop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97940"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-97941",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm/slab: take n->list_lock in __slab_try_return_freelist() to avoid race",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97941"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-97971",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nstree: check listing permission before taking a namespace reference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97971"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-97991",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "vdpa_sim_blk: reject out-of-range sector starts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97991"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-98002",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iommu/amd: Fix ineffective error check in nested domain allocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98002"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-98017",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/sched: defer qdisc freeing after failed creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98017"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-98023",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "vxlan: reject dynamic fdb entries that reference a nexthop id",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98023"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-98052",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: bcmasp: clear txcb->last before writing each descriptor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98052"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-98073",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: Remove conflicting altnames for dying netns in __dev_change_net_namespace().",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98073"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-98112",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ksmbd: fix listener task lifetime on netdev events",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98112"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-98116",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98116"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-98122",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "vxlan: mdb: Fix use-after-free in vxlan_mdb_remote_src_del()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98122"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-98143",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "accel: ethosu: Don't read the U65 rounding mode as a storage mode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98143"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-98156",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/virtio: use the DMA API for resource backing on Xen",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98156"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-49470",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "glpi-project",
      "product": "glpi",
      "cwe": "CWE-307",
      "title": "GLPI: Missing Rate Limiting on Login and TOTP Verification — Account Takeover via Brute Force",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49470"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-67239",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-79",
      "title": "RabbitMQ: Stored XSS via TLS peer-certificate DN in stream-management UI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67239"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-84893",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-89",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84893"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-5267",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ciena",
      "product": "Navigator NCS",
      "cwe": "CWE-306",
      "title": "Unauthenticated Event Stream Exposure of Session Tokens in Navigator NCS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5267"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-10758",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Esri",
      "product": "Lerc",
      "cwe": "CWE-190",
      "title": "Esri Lerc has a security vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10758"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-49850",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "InvoicePlane",
      "product": "InvoicePlane",
      "cwe": "CWE-22",
      "title": "InvoicePlane: Missing CSRF Protection on State-Changing delete Actions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49850"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-50547",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "InvoicePlane",
      "product": "InvoicePlane",
      "cwe": "CWE-22",
      "title": "InvoicePlane permits local file inclusion through the e-invoice XML configuration identifier",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50547"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-52622",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-200",
      "title": "An issue in Wellav Technologies Co., Ltd Wellav WES Emergency Broadcast Terminal WES100, WES270, WES280, and WES290 before 08-08-2023 allows a remote attacker to obtain sensitive information via the global API request wrapper function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52622"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-53610",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "glpi-project",
      "product": "glpi",
      "cwe": "CWE-79",
      "title": "GLPI: Reflected XSS in dashboards",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53610"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-53625",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "glpi-project",
      "product": "glpi",
      "cwe": "CWE-862",
      "title": "GLPI: Privilege Escalation via authtype API manipulation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53625"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-57443",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "issdandavis",
      "product": "SCBE-AETHERMOORE",
      "cwe": "CWE-306",
      "title": "SCBE-AETHERMOORE Unauthenticated AetherBrowser Ops API Exposes Operator Email Digests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57443"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-67237",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-79",
      "title": "RabbitMQ: Reflected XSS via the OAuth bootstrap JS endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67237"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-84882",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-22",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84882"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-84884",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-256",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84884"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-85029",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-22",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85029"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-88003",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "InvoicePlane",
      "product": "InvoicePlane",
      "cwe": "CWE-863",
      "title": "InvoicePlane: Failure to Revoke Administrative Privileges After Role Downgrade",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88003"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-88421",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-284",
      "title": "Incorrect access control in the BlogPage.get_entries() component of APSL puput v1.2.1 through v2.2.0 allows unauthenticated attackers to view restricted blog entries via the blog index, the tag, category, author and date archives, the sidebar widgets, or the RSS feed.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88421"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-91765",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PHP Group",
      "product": "PHP",
      "cwe": "CWE-674",
      "title": "SOAP: Unbounded Recursion in Server-Side cleanup_xml_node",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91765"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-97523",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mptcp: close race between scheduler and state change",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97523"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-97524",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mptcp: avoid unneeded actions on subflow reset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97524"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-97531",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: qla2xxx: Skip vport under deletion in report ID acquisition",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97531"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-97536",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: qla2xxx: Fix use-after-free of qpair work on queue teardown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97536"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-97557",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: client: avoid leaking refcount in cifs_queue_oplock_break()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97557"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-97562",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: client: pin DFS superblock in iterator callback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97562"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-97583",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "afs: Clear stale peer app data after address list changes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97583"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-97595",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mac802154: fix use-after-free of sdata via queued RX frames",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97595"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-97990",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "vdpa_sim_net: check TX pull result before RX copy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97990"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-98050",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mlxsw: spectrum_ptp: Fix napi_gro_receive() call from GC workqueue context",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98050"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-98056",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nvme: remove stale namespaces by NSID range during scan",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98056"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-98108",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: L2CAP: fix chan mode for LE_CONN_REQ + EXT_FLOWCTL pchan",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98108"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-100208",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-190",
      "title": "Microsoft Office Outlook Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100208"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-98096",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipv6: sr: restore network header before routing and forwarding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98096"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-100310",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU",
      "product": "libextractor",
      "cwe": "CWE-426",
      "title": "GNU libextractor before 1.16 Privilege Escalation via LIBEXTRACTOR_PREFIX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100310"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-100419",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitoxideLabs",
      "product": "gitoxide",
      "cwe": "CWE-59",
      "title": "gitoxide gix-fs before 0.23.0 Worktree Escape via Symlink",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100419"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-33639",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "InvoicePlane",
      "product": "InvoicePlane",
      "cwe": "CWE-89",
      "title": "InvoicePlane permits DDL injection through tax_rate_decimal_places",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33639"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-42323",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Piwigo",
      "product": "Piwigo",
      "cwe": "CWE-89",
      "title": "Piwigo: SQL Injection in Batch Manager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42323"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-42324",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Piwigo",
      "product": "Piwigo",
      "cwe": "CWE-89",
      "title": "Piwigo: Second-Order SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42324"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-84862",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-502",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84862"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-85750",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Piwigo",
      "product": "Piwigo",
      "cwe": "CWE-20",
      "title": "Piwigo arbitrary file read and remote code execution via insecure image processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85750"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-100387",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pgpointcloud",
      "product": "pointcloud",
      "cwe": "CWE-125",
      "title": "pgPointcloud through 1.2.5 heap out-of-bounds read via WKB deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100387"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-53626",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "glpi-project",
      "product": "glpi",
      "cwe": "CWE-639",
      "title": "GLPI: Arbitrary Document Read via Form Context Authorization Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53626"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-53629",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "glpi-project",
      "product": "glpi",
      "cwe": "CWE-89",
      "title": "GLPI: SQL injection in history tab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53629"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-56723",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zammad",
      "product": "zammad",
      "cwe": "CWE-863",
      "title": "Zammad: Missing authorization on ticket attachment download",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56723"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-56724",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zammad",
      "product": "zammad",
      "cwe": "CWE-639",
      "title": "Zammad: Incorrect implementation of permission checks in the knowledge base module",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56724"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-56727",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zammad",
      "product": "zammad",
      "cwe": "CWE-287",
      "title": "Zammad: PGP signature spoofing via unvalidated verification return",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56727"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-57449",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "actualbudget",
      "product": "actual",
      "cwe": "CWE-200",
      "title": "Actual Sync Server: CORS Proxy GitHub API Allowlist Prefix Bypass Leaks Private Repositories Through the Server GitHub Token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57449"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-67408",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-400",
      "title": "RabbitMQ: Stream Management Super-Stream Binding Keys Allocation Allows Low-Privilege Node Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67408"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-67419",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-407",
      "title": "RabbitMQ: Consecutive topic wildcards cause combinatorial routing work",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67419"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-84464",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zammad",
      "product": "zammad",
      "cwe": "CWE-200",
      "title": "Zammad: IDOR in External Data Source rendering exposes ticket, user, group, and organization data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84464"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-84465",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zammad",
      "product": "zammad",
      "cwe": "CWE-290",
      "title": "Zammad: S/MIME signature verification allows forged sender impersonation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84465"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-93306",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Server Firmware",
      "cwe": "CWE-125",
      "title": "This Power System update is being released to address",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93306"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-93365",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bludit",
      "product": "Bludit CMS",
      "cwe": "CWE-862",
      "title": "Bludit CMS 3.22.0 Missing Authorization via content-get-list AJAX Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93365"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-97589",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "s390/crypto: Fix wrong return code to engine in asynch callbacks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97589"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-97608",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfilter: nf_log: unregister loggers before per-net teardown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97608"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-97609",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfilter: cttimeout: prevent UAF during module unload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97609"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-97926",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ufs: validate cylinder group metadata before caching it",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97926"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-97931",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: us122l: Prevent write upgrades for read mappings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97931"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-97953",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: stmmac: fix TX descriptor availability check for TSO traffic",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97953"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-98027",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: dsa: mv88e6xxx: bound the policy rule dump by the caller's buffer size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98027"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-98029",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "eth: nfp: bound the ntuple rule dump by the caller's buffer size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98029"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-98030",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: dsa: bcm_sf2: bound the CFP rule dump by the caller's buffer size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98030"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-98041",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Don't predict JMP32 pointer vs zero comparisons",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98041"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-98083",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "btrfs: fix transaction use-after-free in raid stripe insertion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98083"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-98150",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Fix BPF_F_CPU validation for sparse CPU IDs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98150"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-98154",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nvme-rdma: fix -EIO cleanup order in queue_rq",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98154"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-17545",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PHP Group",
      "product": "PHP",
      "cwe": "CWE-67",
      "title": "PHP on Windows: Reserved Device Names Are Not Rejected Before File/Stream I/O which can cause DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17545"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-63207",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zammad",
      "product": "zammad",
      "cwe": "CWE-200",
      "title": "Zammad: Sensitive Information Exposure in Integration Administration API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63207"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-67226",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-400",
      "title": "RabbitMQ: Admin-only atom exhaustion: PUT /api/users tags list",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67226"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-84461",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zammad",
      "product": "zammad",
      "cwe": "CWE-203",
      "title": "Zammad: Missing rate limiting allows password brute-forcing during two-factor login",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84461"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-96875",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Wikimedia Foundation",
      "product": "Mediawiki - Cargo extension",
      "cwe": "CWE-79",
      "title": "Reflected XSS in Cargo Drilldown hierarchy filters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96875"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-96876",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Wikimedia Foundation",
      "product": "Mediawiki - Cargo extension",
      "cwe": "CWE-79",
      "title": "Anonymous reflected XSS in CargoExport invalid-alias errors",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96876"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-96877",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Wikimedia Foundation",
      "product": "Mediawiki - Cargo extension",
      "cwe": "CWE-79",
      "title": "Reflected XSS through Cargo Drilldown full-text search",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96877"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-96878",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Wikimedia Foundation",
      "product": "Mediawiki - Cargo extension",
      "cwe": "CWE-79",
      "title": "Cargo Exhibit field alias allows stored XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96878"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-96879",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Wikimedia Foundation",
      "product": "Mediawiki - FlaggedRevs extension",
      "cwe": "CWE-212",
      "title": "\"Checked by\" label in page history should not be shown if the underlying review log entry is suppressed\"",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96879"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-97865",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Open-Web-Analytics",
      "cwe": "CWE-20",
      "title": "Open-Web-Analytics Remote Event Queue Endpoint queue.php loadFromArray deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97865"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-100187",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ail project",
      "product": "ail framework",
      "cwe": "CWE-20",
      "title": "AIL Framework Onion Module: Non-Onion URL Accepted as Crawler Task Due to Bypassed Domain Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100187"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-100192",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yzcheng90",
      "product": "X-SpringBoot",
      "cwe": "CWE-306",
      "title": "X-SpringBoot through 6.0 Credential Exposure via Unauthenticated Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100192"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-100306",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TDuckCloud",
      "product": "tduck-survey-form",
      "cwe": "CWE-602",
      "title": "TDuck survey form through 6.0 Write Password Bypass via Client-Side Enforcement",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100306"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-100377",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wikimedia Foundation",
      "product": "Mediawiki - WikiLambda Extension",
      "cwe": "CWE-200",
      "title": "Revision-deleted pages can be viewed through WikiLambda's action=edit and Special:ViewAbstract",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100377"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-100418",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pawelmalak",
      "product": "flame",
      "cwe": "CWE-200",
      "title": "Flame through 2.4.0 Information Exposure via GET /api/config",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100418"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-80431",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kovid Goyal",
      "product": "kitty",
      "cwe": "CWE-787",
      "title": "Out-of-bounds write in the kitty text sizing protocol allows termination of the terminal process",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80431"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2025-14181",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PHP Group",
      "product": "PHP",
      "cwe": "CWE-190",
      "title": "Integer overflow to buffer overflow in soap HTTP parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-14181"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-63431",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "horilla",
      "product": "horilla-hr",
      "cwe": "CWE-862",
      "title": "Horilla: Missing Authorization on Payroll Component Views Exposes Employee Salary Structures and Personal Loan Records (IDOR)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63431"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-63432",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "horilla",
      "product": "horilla-hr",
      "cwe": "CWE-94",
      "title": "Horilla: Server-Side Template Injection (SSTI) in Mail Preview Endpoints Allows Authenticated Users to Disclose Password Hashes and Server Metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63432"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-85274",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "InvoicePlane",
      "product": "InvoicePlane",
      "cwe": "CWE-352",
      "title": "InvoicePlane: Recurring Invoice State Change via GET Request Without CSRF Protection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85274"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-85289",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "InvoicePlane",
      "product": "InvoicePlane",
      "cwe": "CWE-352",
      "title": "InvoicePlane: Missing CSRF Token Validation on Multiple Delete Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85289"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-85291",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "InvoicePlane",
      "product": "InvoicePlane",
      "cwe": "CWE-639",
      "title": "InvoicePlane IDOR: Horizontal Privilege Escalation via Password Change Without Authorization Check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85291"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-91767",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PHP Group",
      "product": "PHP",
      "cwe": "CWE-122",
      "title": "Heap-buffer-overflow in php_openssl_matches_wildcard_name on crafted server cert wildcard CN",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91767"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-91768",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PHP Group",
      "product": "PHP",
      "cwe": "CWE-1023",
      "title": "IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address comparison (memcmp 12 bytes)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91768"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-93030",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "IBM Financial Transaction Manager (FTM) for Redhat OpenShift",
      "cwe": "CWE-611",
      "title": "FTM 4.x ALL could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity injection flaw.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93030"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-61837",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-285",
      "title": "RabbitMQ: AMQP 1.0 management `GET /bindings` exposes full binding topology to any authenticated AMQP user without resource/management permission checks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61837"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-67223",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-90",
      "title": "RabbitMQ: LDAP DN injection via unescaped substitution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67223"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-67225",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-770",
      "title": "RabbitMQ: Stream-protocol frame length never validated against frame_max",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67225"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-67230",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-770",
      "title": "RabbitMQ: Web-STOMP unbounded pre-auth accumulation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67230"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-67242",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-613",
      "title": "RabbitMQ: OAuth2 is_integer(Exp) guard skips token-expiry checks for float exp",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67242"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-84463",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zammad",
      "product": "zammad",
      "cwe": "CWE-79",
      "title": "Zammad: Stored HTML injection in Knowledge Base video widget enables forced session switching via unescaped iframe attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84463"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-100177",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ail project",
      "product": "ail framework",
      "cwe": "CWE-20",
      "title": "Ail Framework Crawler: Missing Cookiejar Authorization Check Allows Cross-Organization Cookiejar Attachment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100177"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-100190",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ail project",
      "product": "ail framework",
      "cwe": "CWE-79",
      "title": "Stored Cross-Site Scripting (XSS) via Crawler Capture Import in AIL Framework showDomain Page",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100190"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-18311",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Readwise",
      "product": "Reader",
      "cwe": "CWE-79",
      "title": "CVE-2026-18311",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18311"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-18312",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Readwise",
      "product": "Reader",
      "cwe": "CWE-79",
      "title": "CVE-2026-18312",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18312"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-18320",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Readwise",
      "product": "Reader",
      "cwe": "CWE-79",
      "title": "CVE-2026-18320",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18320"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-78902",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "Cross Site Scripting vulnerability in Netgate pfSense 26.03.1-RELEASE allows an attacker to execute arbitrary code via the pfBlockerNG package",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78902"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-100237",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Wikimedia Foundation",
      "product": "Mediawiki - Thanks Extension",
      "cwe": "CWE-79",
      "title": "Stored i18n XSS in the Flow integration of Thanks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100237"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-53627",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "glpi-project",
      "product": "glpi",
      "cwe": "CWE-862",
      "title": "GLPI: Unexpected access to update operations through the API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53627"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-54790",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "InvoicePlane",
      "product": "InvoicePlane",
      "cwe": "CWE-89",
      "title": "InvoicePlane: Second-order SQL injection through the unvalidated custom_field_table field in the Custom Fields module",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54790"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-66071",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-400",
      "title": "RabbitMQ: Atom exhaustion: OAuth2 JWT tag: scope values",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66071"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-66073",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-400",
      "title": "RabbitMQ: Atom table exhaustion via management API node field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66073"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-67411",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-863",
      "title": "RabbitMQ: Web MQTT with PROXY Protocol enabled: a loopback-only user permission bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67411"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-67412",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-862",
      "title": "RabbitMQ: Federation upstream skips vhost authorization allowing cross-vhost message access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67412"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-67413",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-1333",
      "title": "RabbitMQ: Authenticated RabbitMQ JMS Topic Selector Users Can Consume Broker CPU with an Unbounded LIKE Regular Expression",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67413"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-80432",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kovid Goyal",
      "product": "kitty",
      "cwe": "CWE-862",
      "title": "Missing authorization in the kitty drag and drop protocol allows a client to obtain dragged file contents without a drop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80432"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-100304",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TDuckCloud",
      "product": "tduck-survey-form",
      "cwe": "CWE-636",
      "title": "TDuck survey form 6.0 Information Disclosure via Fail-Open Form Ownership Check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100304"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-53628",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "glpi-project",
      "product": "glpi",
      "cwe": "CWE-285",
      "title": "GLPI: Unallowed authentication method update by administrator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53628"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-67222",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-400",
      "title": "RabbitMQ: list_to_atom on auth_mechanism URI tokens in amqp_client",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67222"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-67227",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-400",
      "title": "RabbitMQ: Atom exhaustion: to_atom on global-parameter :name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67227"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-67415",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-400",
      "title": "RabbitMQ: Shovel Management Atom Exhaustion Allows Persistent Broker-Wide Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67415"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-86066",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "horilla",
      "product": "horilla-hr",
      "cwe": "CWE-352",
      "title": "Horilla attendance approval endpoint is vulnerable to cross-site request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86066"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-91766",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PHP Group",
      "product": "PHP",
      "cwe": "CWE-200",
      "title": "Cross-origin credential leak in HTTP stream wrapper redirects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91766"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-92842",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PHP Group",
      "product": "PHP",
      "cwe": "CWE-122",
      "title": "OOB read / info leak in convert.* stream filters when line-break-chars contains NUL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92842"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-100502",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pawelmalak",
      "product": "flame",
      "cwe": "CWE-613",
      "title": "Flame through 2.4.0 Admin Token Insufficient Session Expiration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100502"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-93682",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PHP Group",
      "product": "PHP",
      "cwe": "CWE-125",
      "title": "Out-of-bounds read in the HTTP stream wrapper when following a redirect with an empty Location header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93682"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-95835",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kovid Goyal",
      "product": "kitty",
      "cwe": "CWE-862",
      "title": "Missing ownership check on the shared memory object named by the kitty askpass escape code",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95835"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-97222",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNOME",
      "product": "Gnumeric",
      "cwe": "CWE-416",
      "title": "Gnumeric: gnumeric: heap use-after-free when opening a malformed workbook",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97222"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-97864",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GibbonEdu",
      "product": "Gibbon",
      "cwe": "CWE-287",
      "title": "GibbonEdu Gibbon Unit Planner units_add_blockAjax.php makeBlock missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97864"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-97871",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zhonglun",
      "product": "CloudPos",
      "cwe": "CWE-74",
      "title": "Zhonglun CloudPos JSBridge JSBridge.cs OpenLocalBrowser code injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97871"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-97877",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zhistaredu",
      "product": "StarTraining",
      "cwe": "CWE-255",
      "title": "zhistaredu StarTraining JWT Token application.yml UserLoginService.createToken hard-coded password",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97877"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-97878",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zhistaredu",
      "product": "StarTraining",
      "cwe": "CWE-287",
      "title": "zhistaredu StarTraining Druid Console index.html anonymous missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97878"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-97879",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zhistaredu",
      "product": "StarTraining",
      "cwe": "CWE-287",
      "title": "zhistaredu StarTraining api-docs Endpoint SecurityConfig.java missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97879"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-97882",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mathurvishal",
      "product": "CloudClassroom-PHP-Project",
      "cwe": "CWE-74",
      "title": "mathurvishal CloudClassroom-PHP-Project Faculty Authentication loginlinkfaculty.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97882"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-97883",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mathurvishal",
      "product": "CloudClassroom-PHP-Project",
      "cwe": "CWE-74",
      "title": "mathurvishal CloudClassroom-PHP-Project updatequery.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97883"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-97885",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mathurvishal",
      "product": "CloudClassroom-PHP-Project",
      "cwe": "CWE-74",
      "title": "mathurvishal CloudClassroom-PHP-Project updatefaculty.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97885"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-45801",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "glpi-project",
      "product": "glpi",
      "cwe": "CWE-269",
      "title": "GLPI: Unauthorized Debug Mode Activation via Profile Update (Privilege Escalation)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45801"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-55217",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "glpi-project",
      "product": "glpi",
      "cwe": "CWE-285",
      "title": "GLPI: Unallowed modfication of knowbase items comments and translations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55217"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-56728",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zammad",
      "product": "zammad",
      "cwe": "CWE-200",
      "title": "Zammad: Cross-User Taskbar Item Access Control Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56728"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-56732",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zammad",
      "product": "zammad",
      "cwe": "CWE-20",
      "title": "Zammad: Malicious input in Ticket Body Enables Session Termination",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56732"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-56734",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zammad",
      "product": "zammad",
      "cwe": "CWE-918",
      "title": "Zammad: Avatar Image URL Server-Side Request Forwarding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56734"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-56735",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zammad",
      "product": "zammad",
      "cwe": "CWE-82",
      "title": "Zammad: Improper neutralization of `srcset` attribute in IMG tags in Zammad",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56735"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-61855",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zammad",
      "product": "zammad",
      "cwe": "CWE-347",
      "title": "Zammad: Invalid PGP Detached Signatures Reported as Good Signature on Inbound Mail",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61855"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-63006",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zammad",
      "product": "zammad",
      "cwe": "CWE-22",
      "title": "Zammad: HTML sanitizer API path allowlist bypass via interior path traversal in img src/srcset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63006"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-63206",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zammad",
      "product": "zammad",
      "cwe": "CWE-20",
      "title": "Zammad: Remote image tracking bypass via shortened URL scheme",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63206"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-63216",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zammad",
      "product": "zammad",
      "cwe": "CWE-80",
      "title": "Zammad: Stored XSS via unescaped option labels in the object attribute options context UI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63216"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-84460",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zammad",
      "product": "zammad",
      "cwe": "CWE-639",
      "title": "Zammad: Missing Authorization in TagsController#list Allows Cross-Object Tag Enumeration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84460"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-85290",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "InvoicePlane",
      "product": "InvoicePlane",
      "cwe": "CWE-117",
      "title": "InvoicePlane: Log Injection via Unsanitized User Input in Cron Key Error Logging",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85290"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-93363",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "payloadcms",
      "product": "payload",
      "cwe": "CWE-862",
      "title": "Payload CMS storage-vercel-blob Adapter Improper Access Control on Upload Route",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93363"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-93364",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bludit",
      "product": "Bludit CMS",
      "cwe": "CWE-915",
      "title": "Bludit CMS 3.22.0 Mass Assignment Privilege Escalation via Pages::edit()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93364"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-93366",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bludit",
      "product": "Bludit CMS",
      "cwe": "CWE-639",
      "title": "Bludit CMS 3.22.0 Authorization Bypass via list-images/delete-image AJAX Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93366"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-100230",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "input-leap",
      "product": "Input Leap",
      "cwe": "CWE-180",
      "title": "Input Leap (aka input-leap) through 3.0.3, when the non-default --enable-drag-drop option is used on Windows or macOS, mishandles the / versus \\ distinction and allows directory traversal, with resultant code execution if a file is written to a startup directory. This occurs via a DDRG message.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100230"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-100303",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TDuckCloud",
      "product": "tduck-survey-form",
      "cwe": "CWE-862",
      "title": "TDuck survey form through 6.0 Missing Authorization in Form Theme Management Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100303"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-100305",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TDuckCloud",
      "product": "tduck-survey-form",
      "cwe": "CWE-862",
      "title": "TDuck survey form through 6.0 Fill-In Restriction Bypass via Authenticated Submission Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100305"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-100378",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wikimedia Foundation",
      "product": "Mediawiki - Translate Extension",
      "cwe": "CWE-862",
      "title": "Missing permission check in the Translate sandbox doRemind action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100378"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-100379",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wikimedia Foundation",
      "product": "Wikipedia Android App",
      "cwe": "CWE-200",
      "title": "Cross-request disclosure of CentralAuth cookies in Wikipedia Android App",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100379"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-100380",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wikimedia Foundation",
      "product": "Mediawiki - Wikibase Extension",
      "cwe": "CWE-79",
      "title": "Reflected XSS in Wikibase Special:SetLabel language validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100380"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-100381",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wikimedia Foundation",
      "product": "Mediawiki - UploadWizard Extension",
      "cwe": "CWE-79",
      "title": "UploadWizard Flickr collection and set titles allow DOM XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100381"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-100388",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rustdesk",
      "product": "rustdesk",
      "cwe": "CWE-862",
      "title": "RustDesk before 1.5.0 Missing Authorization Check on Incoming File Clipboard Messages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100388"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-56726",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zammad",
      "product": "zammad",
      "cwe": "CWE-862",
      "title": "Zammad: Missing authorization check in GitHub + GitLab integration allows cross-ticket data leak",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56726"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-63205",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zammad",
      "product": "zammad",
      "cwe": "CWE-639",
      "title": "Zammad: Channel admins can read unauthorized attachments via signature rich-text body",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63205"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-63208",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zammad",
      "product": "zammad",
      "cwe": "CWE-116",
      "title": "Zammad: Microsoft Graph error logs expose partially masked OAuth access tokens",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63208"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-67407",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-862",
      "title": "RabbitMQ: Incomplete fix for CVE-2026-44838: `escape_regex_char/1` does not escape `-`, leaving room for an MQTT topic permission bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67407"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-97897",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Krayin",
      "product": "laravel-crm",
      "cwe": "CWE-79",
      "title": "Krayin laravel-crm TinyMCE Media Upload Sanitizer.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97897"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-100174",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ail project",
      "product": "ail framework",
      "cwe": "CWE-79",
      "title": "Stored Cross-Site Scripting (XSS) in AIL Framework Tag Selector via Unescaped Tag Names",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100174"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-100373",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-metadata",
      "product": "OpenMetadata",
      "cwe": "CWE-918",
      "title": "OpenMetadata through 2.0.2 SSRF via Webhook URL Validation Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100373"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-39372",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "InvoicePlane",
      "product": "InvoicePlane",
      "cwe": "CWE-200",
      "title": "InvoicePlane: Sensitive Information Disclosure via Unstripped EXIF Metadata in Attachments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39372"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-27867",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Teldat",
      "product": "Regesta Smart HD-PLC - TLDPH16D2",
      "cwe": "CWE-79",
      "title": "CROSS-SITE SCRIPTING (XSS) VIA THE CMDCOOKIE PARAMETER REGESTA SMART HD-PLC OF TELDAT",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27867"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-67241",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-862",
      "title": "RabbitMQ: AMQP 1.0 management exchange.declare skips alternate-exchange permission check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67241"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-85292",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "InvoicePlane",
      "product": "InvoicePlane",
      "cwe": "CWE-697",
      "title": "InvoicePlane: Loose Type Comparison in Core Authentication Check (Defense-in-Depth)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85292"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-85293",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "InvoicePlane",
      "product": "InvoicePlane",
      "cwe": "CWE-79",
      "title": "InvoicePlane: Stored Cross-Site Scripting (XSS) via Client Email in Invoice and Quote Mailer Forms",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85293"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2026-100376",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wikimedia Foundation",
      "product": "Mediawiki - TemplateSandbox Extension",
      "cwe": "CWE-79",
      "title": "TemplateSandbox can be abused for XSS by asking another user to preview a page with a certain sandbox prefix",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100376"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-100383",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wikimedia Foundation",
      "product": "Mediawiki - WikiLambda Extension",
      "cwe": "CWE-79",
      "title": "Stored i18n XSS in WikiLambda's VisualEditor integration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100383"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-49469",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "glpi-project",
      "product": "glpi",
      "cwe": "CWE-90",
      "title": "GLPI: LDAP filter injection in user import feature",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49469"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-67406",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-200",
      "title": "RabbitMQ: Federation and Shovel Gen-Servers Lack format_status Callback — Plaintext Credentials Exposed in Crash Dumps and sys:get_status",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67406"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-80430",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kovid Goyal",
      "product": "kitty",
      "cwe": "CWE-59",
      "title": "Improper link resolution in the kitty drag and drop protocol allows a client to create files outside the staging directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80430"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-95834",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kovid Goyal",
      "product": "kitty",
      "cwe": "CWE-416",
      "title": "Use after free in the kitty drag and drop protocol when a drag source item is aborted mid-transfer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95834"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2026-67421",
      "cvss_base": 4.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-862",
      "title": "RabbitMQ: Stored HTML Injection in RabbitMQ Management OAuth Error Handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67421"
    },
    {
      "rank": 354,
      "cve_id": "CVE-2026-6103",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PHP Group",
      "product": "PHP",
      "cwe": "CWE-190",
      "title": "Phar TAR phar_tar_number() Integer Overflow - Archive Entry Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6103"
    },
    {
      "rank": 355,
      "cve_id": "CVE-2026-91769",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PHP Group",
      "product": "PHP",
      "cwe": "CWE-297",
      "title": "TLS Hostname Verification Falls Back to CN After SAN Mismatch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91769"
    },
    {
      "rank": 356,
      "cve_id": "CVE-2026-97469",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DALIBO",
      "product": "PostgreSQL Anonymizer",
      "cwe": "CWE-328",
      "title": "PostgreSQL Anonymizer: RESTRICTED functions are reachable through a subLink",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97469"
    },
    {
      "rank": 357,
      "cve_id": "CVE-2025-1218",
      "cvss_base": 3.4,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PHP Group",
      "product": "PHP",
      "cwe": "CWE-122",
      "title": "Various packet overreads in mysqlnd_writeprotocol.c",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-1218"
    },
    {
      "rank": 358,
      "cve_id": "CVE-2026-97866",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zhonglun",
      "product": "CloudPOS",
      "cwe": "CWE-300",
      "title": "Zhonglun CloudPOS Automatic Update Program.cs channel accessible",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97866"
    },
    {
      "rank": 359,
      "cve_id": "CVE-2026-97228",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rapid7",
      "product": "Platform",
      "cwe": "CWE-943",
      "title": "Rapid7 Bulk Export MCP — GraphQL Query Injection in Export Status Lookup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97228"
    },
    {
      "rank": 360,
      "cve_id": "CVE-2026-63204",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zammad",
      "product": "zammad",
      "cwe": "CWE-639",
      "title": "Zammad: Authenticated agents can read AI summary error messages from inaccessible tickets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63204"
    },
    {
      "rank": 361,
      "cve_id": "CVE-2026-65828",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zammad",
      "product": "zammad",
      "cwe": "CWE-862",
      "title": "Zammad: Pending upload deletion bypass via legacy attachment endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65828"
    },
    {
      "rank": 362,
      "cve_id": "CVE-2026-67234",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-20",
      "title": "RabbitMQ: Non-RFC-conformant cookie name when clearing the auth-mechanism preference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67234"
    },
    {
      "rank": 363,
      "cve_id": "CVE-2026-67420",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-862",
      "title": "RabbitMQ OAuth credential refresh retains revoked runtime tags",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67420"
    },
    {
      "rank": 364,
      "cve_id": "CVE-2026-96874",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Wikimedia Foundation",
      "product": "Mediawiki - Cargo extension",
      "cwe": "CWE-79",
      "title": "Stored XSS in Cargo Drilldown tab names",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96874"
    },
    {
      "rank": 365,
      "cve_id": "CVE-2026-100417",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rustdesk",
      "product": "rustdesk",
      "cwe": "CWE-862",
      "title": "RustDesk before 1.5.0 One-Way File Transfer Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100417"
    },
    {
      "rank": 366,
      "cve_id": "CVE-2026-56729",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zammad",
      "product": "zammad",
      "cwe": "CWE-200",
      "title": "Zammad: Titles of knowledge base answers will be shown across all categories via the global search",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56729"
    },
    {
      "rank": 367,
      "cve_id": "CVE-2026-56730",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zammad",
      "product": "zammad",
      "cwe": "CWE-862",
      "title": "Zammad: Missing authorization in GraphQL mutation for suggesting knowledge base answers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56730"
    },
    {
      "rank": 368,
      "cve_id": "CVE-2026-66078",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-862",
      "title": "RabbitMQ: protected tag bypass via bulk-delete",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66078"
    },
    {
      "rank": 369,
      "cve_id": "CVE-2026-97884",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mathurvishal",
      "product": "CloudClassroom-PHP-Project",
      "cwe": "CWE-74",
      "title": "mathurvishal CloudClassroom-PHP-Project Student Update Functionality updatestudent.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97884"
    },
    {
      "rank": 370,
      "cve_id": "CVE-2026-97886",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mathurvishal",
      "product": "CloudClassroom-PHP-Project",
      "cwe": "CWE-74",
      "title": "mathurvishal CloudClassroom-PHP-Project managevideos2.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97886"
    },
    {
      "rank": 371,
      "cve_id": "CVE-2026-97895",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "krayin",
      "product": "laravel-crm",
      "cwe": "CWE-266",
      "title": "krayin laravel-crm User Management UserController.php privileges management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97895"
    },
    {
      "rank": 372,
      "cve_id": "CVE-2026-97868",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sheshbabu",
      "product": "zen",
      "cwe": "CWE-79",
      "title": "sheshbabu zen Note Editor NotesEditor.jsx dangerouslySetInnerHTML cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97868"
    },
    {
      "rank": 373,
      "cve_id": "CVE-2026-97896",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "krayin",
      "product": "laravel-crm",
      "cwe": "CWE-79",
      "title": "krayin laravel-crm Upload Functionality ConfigurationForm.php rules cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97896"
    },
    {
      "rank": 374,
      "cve_id": "CVE-2026-97869",
      "cvss_base": 1.2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "langchain4j",
      "cwe": "CWE-20",
      "title": "langchain4j LangChain4j-agentic AgenticScopeJsonSerializationIT.java AgenticScopeSerializer.fromJson deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97869"
    },
    {
      "rank": 375,
      "cve_id": "CVE-2026-51772",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "A Server-Side Request Forgery (SSRF) vulnerability exists in the Image API (v2) of OpenStack Glance. When the show_multiple_locations configuration option is enabled in glance-api.conf, an authenticated attacker can manipulate the locations attribute of an image in the queued state by sending a crafted HTTP PATCH request",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51772"
    },
    {
      "rank": 376,
      "cve_id": "CVE-2026-88389",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Espruino 2v29 (commit bffc6d0) contains a NULL pointer dereference vulnerability in jslGetRawString() in src/jslex.c. Crafted raw/binary string input can cause the lexer to pass a NULL iterator target to jsvLockAgain(). In RELEASE/NO_ASSERT builds, the missing assertion guard allows a write through the NULL pointer, resulting in memory corruption and application termination or denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88389"
    },
    {
      "rank": 377,
      "cve_id": "CVE-2026-88420",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "A reflected cross-site scripting (XSS) vulnerability in the EntryAbstract.save() component of APSL puput v1.2.1 through v2.2.0 allows authenticated attackers with Wagtail Editor privileges to execute arbitrary code in the context of the victim's browser via a crafted payload.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88420"
    },
    {
      "rank": 378,
      "cve_id": "CVE-2026-97522",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mptcp: fix bad accounting in __mptcp_subflow_push_pending()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97522"
    },
    {
      "rank": 379,
      "cve_id": "CVE-2026-97526",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "s390/pai: Support CPU hotplug for PMU PAI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97526"
    },
    {
      "rank": 380,
      "cve_id": "CVE-2026-97529",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: qla2xxx: Validate BSG request_len before reading vendor_cmd[]",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97529"
    },
    {
      "rank": 381,
      "cve_id": "CVE-2026-97530",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: qla2xxx: Fix soft lockup polling continuation IOCB signature",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97530"
    },
    {
      "rank": 382,
      "cve_id": "CVE-2026-97532",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: qla2xxx: Null out freed pointers in qla2x00_mem_alloc() error path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97532"
    },
    {
      "rank": 383,
      "cve_id": "CVE-2026-97533",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "x86/mm/pat: Acquire init_mm read lock on attribute changes to avoid UAF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97533"
    },
    {
      "rank": 384,
      "cve_id": "CVE-2026-97534",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "f2fs: accurately adjust free_sections during free_segment_range",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97534"
    },
    {
      "rank": 385,
      "cve_id": "CVE-2026-97535",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: qla2xxx: Bound VP index against VP_CTRL IOCB bitmap size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97535"
    },
    {
      "rank": 386,
      "cve_id": "CVE-2026-97537",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: qla2xxx: Fix queue teardown NULL dma_free and bitmap locking",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97537"
    },
    {
      "rank": 387,
      "cve_id": "CVE-2026-97538",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "hwmon: (asus_rog_ryujin) Validate HID report lengths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97538"
    },
    {
      "rank": 388,
      "cve_id": "CVE-2026-97539",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: xusbatm: don't rely on id table pointer arithmetic",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97539"
    },
    {
      "rank": 389,
      "cve_id": "CVE-2026-97540",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: usb: pegasus: don't rely on id table pointer arithmetic",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97540"
    },
    {
      "rank": 390,
      "cve_id": "CVE-2026-97541",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: ath9k_htc: don't store usb_device_id",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97541"
    },
    {
      "rank": 391,
      "cve_id": "CVE-2026-97542",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfs: bail out on bitmap errors in xrep_agfl_fill",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97542"
    },
    {
      "rank": 392,
      "cve_id": "CVE-2026-97543",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfs: destroy seen inode bitmap when we fail to add a dirpath",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97543"
    },
    {
      "rank": 393,
      "cve_id": "CVE-2026-97544",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfs: don't leak dqacct if rhashtable insertion fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97544"
    },
    {
      "rank": 394,
      "cve_id": "CVE-2026-97545",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfs: don't leak new_bp if xfs_btree_bload_drop_buf fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97545"
    },
    {
      "rank": 395,
      "cve_id": "CVE-2026-97546",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfs: don't spin forever on zero-length dirents when salvaging them",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97546"
    },
    {
      "rank": 396,
      "cve_id": "CVE-2026-97547",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97547"
    },
    {
      "rank": 397,
      "cve_id": "CVE-2026-97549",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfs: fix under-reservation of blocks when repairing sf directories",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97549"
    },
    {
      "rank": 398,
      "cve_id": "CVE-2026-97550",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfs: fix unit conversions in per_binval computation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97550"
    },
    {
      "rank": 399,
      "cve_id": "CVE-2026-97551",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfs: initialise args->total for parent pointer updates",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97551"
    },
    {
      "rank": 400,
      "cve_id": "CVE-2026-97552",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfs: initialise error in xfs_defer_finish_one()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97552"
    },
    {
      "rank": 401,
      "cve_id": "CVE-2026-97553",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfs: lock the healthmon when inserting unmount event",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97553"
    },
    {
      "rank": 402,
      "cve_id": "CVE-2026-97554",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: client: avoid using uninitialized SIDs in cifs_posix_to_fattr()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97554"
    },
    {
      "rank": 403,
      "cve_id": "CVE-2026-97556",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: client: avoid leaking refcount when cifs_sb_tlink() fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97556"
    },
    {
      "rank": 404,
      "cve_id": "CVE-2026-97558",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: client: fix cifsFileInfo reference leak in deferred close",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97558"
    },
    {
      "rank": 405,
      "cve_id": "CVE-2026-97559",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: client: fail DACL rewrite when the new DACL exceeds 64K",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97559"
    },
    {
      "rank": 406,
      "cve_id": "CVE-2026-97560",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: client: fix one-byte OOB read in smb2_parse_native_symlink()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97560"
    },
    {
      "rank": 407,
      "cve_id": "CVE-2026-97561",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: client: honor forceuid/forcegid when mapping SIDs to uid/gid",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97561"
    },
    {
      "rank": 408,
      "cve_id": "CVE-2026-97563",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: client: reject out-of-bounds DataOffset in CIFSSMBRead()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97563"
    },
    {
      "rank": 409,
      "cve_id": "CVE-2026-97564",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: client: reject userspace cifs.idmap descriptions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97564"
    },
    {
      "rank": 410,
      "cve_id": "CVE-2026-97565",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: client: reject short READ responses in CIFSSMBRead()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97565"
    },
    {
      "rank": 411,
      "cve_id": "CVE-2026-97566",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mptcp: pm: kernel: drop pending ADD_ADDR when removing ID0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97566"
    },
    {
      "rank": 412,
      "cve_id": "CVE-2026-97567",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mptcp: prevent race between disconnect() and rtx",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97567"
    },
    {
      "rank": 413,
      "cve_id": "CVE-2026-97568",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mptcp: syncookies: remember the request backup flag",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97568"
    },
    {
      "rank": 414,
      "cve_id": "CVE-2026-97569",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bnxt_en: Prevent queue stop with deferred completions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97569"
    },
    {
      "rank": 415,
      "cve_id": "CVE-2026-97571",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bnxt_en: Propagate TPA buffer allocation failures in bnxt_queue_mem_alloc()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97571"
    },
    {
      "rank": 416,
      "cve_id": "CVE-2026-97572",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bnxt_en: Propagate RX ring init failures in bnxt_init_nic()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97572"
    },
    {
      "rank": 417,
      "cve_id": "CVE-2026-97574",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bnxt_en: Don't free the live ring's TPA state on queue restart failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97574"
    },
    {
      "rank": 418,
      "cve_id": "CVE-2026-97581",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: verisilicon: hantro: bound G2 HEVC tile loop to the buffer capacity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97581"
    },
    {
      "rank": 419,
      "cve_id": "CVE-2026-97582",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "hwmon: (gpio-fan) Fix use-after-free in alarm work",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97582"
    },
    {
      "rank": 420,
      "cve_id": "CVE-2026-97585",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "afs: Fix double-unmap of directory block",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97585"
    },
    {
      "rank": 421,
      "cve_id": "CVE-2026-97586",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "afs: Fix missing kunmap in afs_dir_search_bucket()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97586"
    },
    {
      "rank": 422,
      "cve_id": "CVE-2026-97587",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "perf: RISC-V: store available counter mask as bitmap",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97587"
    },
    {
      "rank": 423,
      "cve_id": "CVE-2026-97588",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "s390/crypto: Map EBUSY to EIO when key conversion fails repeatedly",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97588"
    },
    {
      "rank": 424,
      "cve_id": "CVE-2026-97590",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "s390/crypto: Fix missing scrub of temp buffers with PAES algorithm",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97590"
    },
    {
      "rank": 425,
      "cve_id": "CVE-2026-97591",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "s390/crypto: Fix handling of EBUSY in PHMAC when req is pushed to crypto engine",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97591"
    },
    {
      "rank": 426,
      "cve_id": "CVE-2026-97592",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "s390/crypto: Fix missing scrub of temp buffers with AES ctr and gcm algorithm",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97592"
    },
    {
      "rank": 427,
      "cve_id": "CVE-2026-97593",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iommu/s390: Fix NULL dereference in iova_to_phys() with ZPCI_TABLE_TYPE_RFX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97593"
    },
    {
      "rank": 428,
      "cve_id": "CVE-2026-97596",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipvs: reject invalid states in connection template sync records",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97596"
    },
    {
      "rank": 429,
      "cve_id": "CVE-2026-97597",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipv6: flowlabel: cap duplicate leases per socket",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97597"
    },
    {
      "rank": 430,
      "cve_id": "CVE-2026-97598",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipv4: fib: bound automatic table ID allocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97598"
    },
    {
      "rank": 431,
      "cve_id": "CVE-2026-97599",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ieee802154: hwsim: serialize pib updates to fix double-free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97599"
    },
    {
      "rank": 432,
      "cve_id": "CVE-2026-97600",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ieee802154: cc2520: fix FIFOP work use-after-free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97600"
    },
    {
      "rank": 433,
      "cve_id": "CVE-2026-97601",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ieee802154: 6lowpan: fix NULL dereference in lowpan_newlink",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97601"
    },
    {
      "rank": 434,
      "cve_id": "CVE-2026-97603",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "idpf: disable DIM work before freeing q_vectors",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97603"
    },
    {
      "rank": 435,
      "cve_id": "CVE-2026-97604",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fbdev: vfb: defer cleanup until the last reference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97604"
    },
    {
      "rank": 436,
      "cve_id": "CVE-2026-97605",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "erofs: preserve LZMA decoders on resize failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97605"
    },
    {
      "rank": 437,
      "cve_id": "CVE-2026-97606",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fs: autofs: fix memory leak in autofs_fill_super()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97606"
    },
    {
      "rank": 438,
      "cve_id": "CVE-2026-97607",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "vdpa: ifcvf: Put device on unsupported feature error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97607"
    },
    {
      "rank": 439,
      "cve_id": "CVE-2026-97610",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfs: Fix uninitialized return value in netfs_unbuffered_write()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97610"
    },
    {
      "rank": 440,
      "cve_id": "CVE-2026-97613",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: mana: Reserve extra CQ slot for the fence completion CQE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97613"
    },
    {
      "rank": 441,
      "cve_id": "CVE-2026-97614",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: dsa: tag_brcm: legacy FCS: request needed tailroom",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97614"
    },
    {
      "rank": 442,
      "cve_id": "CVE-2026-97615",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: bridge: use option bits for CFM/MRP frame handlers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97615"
    },
    {
      "rank": 443,
      "cve_id": "CVE-2026-97616",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/sched: act_api: release all action references on NEWACTION failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97616"
    },
    {
      "rank": 444,
      "cve_id": "CVE-2026-97617",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ring-buffer: Check resize_disabled before publishing the new subbuf order",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97617"
    },
    {
      "rank": 445,
      "cve_id": "CVE-2026-97618",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "io_uring/net: don't overconsume buffers when using MSG_TRUNC",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97618"
    },
    {
      "rank": 446,
      "cve_id": "CVE-2026-97619",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "io_uring/rw: end write accounting from ->ki_complete",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97619"
    },
    {
      "rank": 447,
      "cve_id": "CVE-2026-97620",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/xe: Flush LSC untyped L1 dataport cache after rcs/ccs batches",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97620"
    },
    {
      "rank": 448,
      "cve_id": "CVE-2026-97621",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/rockchip: analogix_dp: fix unchecked bound endpoint name length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97621"
    },
    {
      "rank": 449,
      "cve_id": "CVE-2026-97899",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/i915: Fix memory leak in query_perf_config_list()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97899"
    },
    {
      "rank": 450,
      "cve_id": "CVE-2026-97900",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/drm_exec: fix up contended obj when num_objects is 0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97900"
    },
    {
      "rank": 451,
      "cve_id": "CVE-2026-97901",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "genetlink: pin family module during policy dump",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97901"
    },
    {
      "rank": 452,
      "cve_id": "CVE-2026-97902",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fs: don't return -EINVAL for successful nested thaw",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97902"
    },
    {
      "rank": 453,
      "cve_id": "CVE-2026-97904",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "cpufreq: initialize policy rwsem before sysfs publication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97904"
    },
    {
      "rank": 454,
      "cve_id": "CVE-2026-97905",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "cpufreq: zero-initialize policy cpumask before sysfs publication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97905"
    },
    {
      "rank": 455,
      "cve_id": "CVE-2026-97906",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bootconfig: Fix integer overflow in initrd size check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97906"
    },
    {
      "rank": 456,
      "cve_id": "CVE-2026-97907",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: btrtl: Don't leak return code when parsing firmware format v2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97907"
    },
    {
      "rank": 457,
      "cve_id": "CVE-2026-97908",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: btqcomsmd: destroy RPMsg endpoints before freeing hci_dev",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97908"
    },
    {
      "rank": 458,
      "cve_id": "CVE-2026-97909",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ASoC: sti: initialize IRQ lock before requesting IRQ",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97909"
    },
    {
      "rank": 459,
      "cve_id": "CVE-2026-97912",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "accel: ethosu: Ensure SRAM size is 0 on mapping failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97912"
    },
    {
      "rank": 460,
      "cve_id": "CVE-2026-97913",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "accel: ethosu: Ensure cmd stream ends with a stop op",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97913"
    },
    {
      "rank": 461,
      "cve_id": "CVE-2026-97914",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "accel: ethosu: Fix ethosu_job_open() return value",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97914"
    },
    {
      "rank": 462,
      "cve_id": "CVE-2026-97915",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "accel/ivpu: Limit firmware log name prints to field size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97915"
    },
    {
      "rank": 463,
      "cve_id": "CVE-2026-97916",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "accel/ivpu: Validate firmware log buffer metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97916"
    },
    {
      "rank": 464,
      "cve_id": "CVE-2026-97917",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "accel/ivpu: Validate full buffer range in ivpu_to_cpu_addr",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97917"
    },
    {
      "rank": 465,
      "cve_id": "CVE-2026-97918",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tracing: Undo the registration when enabling the histogram trigger fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97918"
    },
    {
      "rank": 466,
      "cve_id": "CVE-2026-97919",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tracing: Take the reference before publishing the named histogram trigger",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97919"
    },
    {
      "rank": 467,
      "cve_id": "CVE-2026-97920",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tracing: Keep the entry count when the histogram stats allocation fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97920"
    },
    {
      "rank": 468,
      "cve_id": "CVE-2026-97921",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tracing: Free histogram the field rejected for a bad modifier",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97921"
    },
    {
      "rank": 469,
      "cve_id": "CVE-2026-97922",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tracing: Free histogram var refs regardless of how often they are referenced",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97922"
    },
    {
      "rank": 470,
      "cve_id": "CVE-2026-97923",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tracing: Free histogram the var ref when its initialization fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97923"
    },
    {
      "rank": 471,
      "cve_id": "CVE-2026-97924",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tracing/user_events: Don't destroy fields when event removal fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97924"
    },
    {
      "rank": 472,
      "cve_id": "CVE-2026-97925",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tick/broadcast: Plug clockevents replacement race",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97925"
    },
    {
      "rank": 473,
      "cve_id": "CVE-2026-97927",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ufs: create the root dentry after loading cylinder metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97927"
    },
    {
      "rank": 474,
      "cve_id": "CVE-2026-97928",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu: skip the VMID 0 flush for VRAM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97928"
    },
    {
      "rank": 475,
      "cve_id": "CVE-2026-97929",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: usbusx2y: validate URB actual_length in interrupt callback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97929"
    },
    {
      "rank": 476,
      "cve_id": "CVE-2026-97930",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: usbusx2y: fix in04_last array size mismatch with in04_buf",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97930"
    },
    {
      "rank": 477,
      "cve_id": "CVE-2026-97932",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tracing: Don't dereference trace_event_file in deferred trigger free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97932"
    },
    {
      "rank": 478,
      "cve_id": "CVE-2026-97933",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tracing: Take trace_array reference when opening a tracer options file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97933"
    },
    {
      "rank": 479,
      "cve_id": "CVE-2026-97934",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tracing: Fix memory corruption from a \"STACKTRACE\" histogram key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97934"
    },
    {
      "rank": 480,
      "cve_id": "CVE-2026-97935",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tracing: Set the trace clock before registering the histogram trigger",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97935"
    },
    {
      "rank": 481,
      "cve_id": "CVE-2026-97936",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tracing: Fix memory corruption from the histogram stacktrace modifier",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97936"
    },
    {
      "rank": 482,
      "cve_id": "CVE-2026-97938",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "reboot: fix cad_pid use-after-free race",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97938"
    },
    {
      "rank": 483,
      "cve_id": "CVE-2026-97939",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipmr: account multicast table and route memory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97939"
    },
    {
      "rank": 484,
      "cve_id": "CVE-2026-97942",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "x86/alternatives: Exclude text poking against change_page_attr()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97942"
    },
    {
      "rank": 485,
      "cve_id": "CVE-2026-97943",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "x86/mm/pat: Acquire init_mm write lock on collapse to avoid UAF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97943"
    },
    {
      "rank": 486,
      "cve_id": "CVE-2026-97944",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "x86/cfi: Fix FineIBT hash offset in cfi_get_func_hash()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97944"
    },
    {
      "rank": 487,
      "cve_id": "CVE-2026-97945",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "x86/mm: Fix user-space data loss with MADV_FREE and THP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97945"
    },
    {
      "rank": 488,
      "cve_id": "CVE-2026-97946",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "x86/amd_node: Fix PCI device reference counting in amd_smn_init()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97946"
    },
    {
      "rank": 489,
      "cve_id": "CVE-2026-97947",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "x86/amd_node: Fix potential NULL pointer dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97947"
    },
    {
      "rank": 490,
      "cve_id": "CVE-2026-97948",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "powerpc/eeh: Fix recursive locking on devices without EEH sensitive driver",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97948"
    },
    {
      "rank": 491,
      "cve_id": "CVE-2026-97949",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "configfs: unhash the dentry before dropping the item in rmdir",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97949"
    },
    {
      "rank": 492,
      "cve_id": "CVE-2026-97950",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "configfs: pin the symlink target's dirent instead of chasing ->ci_dentry",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97950"
    },
    {
      "rank": 493,
      "cve_id": "CVE-2026-97951",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: target: iscsi: Fix hang for aborted WRITE_PENDING commands",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97951"
    },
    {
      "rank": 494,
      "cve_id": "CVE-2026-97952",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "sunvdc: unmap LDC cookies when the descriptor send fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97952"
    },
    {
      "rank": 495,
      "cve_id": "CVE-2026-97954",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/rds: fix tcp stream corruption with large pages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97954"
    },
    {
      "rank": 496,
      "cve_id": "CVE-2026-97955",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: mana: restore the XDP program pointer when pre-allocation fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97955"
    },
    {
      "rank": 497,
      "cve_id": "CVE-2026-97956",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: net_failover: Fix the deadlock in net_failover_slave_name_change()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97956"
    },
    {
      "rank": 498,
      "cve_id": "CVE-2026-97958",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/sched: cls_api: Don't replay RTM_GETCHAIN in tc_ctl_chain().",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97958"
    },
    {
      "rank": 499,
      "cve_id": "CVE-2026-97959",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/sched: cls_route: free emptied bucket on filter move",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97959"
    },
    {
      "rank": 500,
      "cve_id": "CVE-2026-97960",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "perf/x86/intel: Prevent drain_pebs() reentry",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97960"
    },
    {
      "rank": 501,
      "cve_id": "CVE-2026-97961",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "perf/core: Allow list_del during perf_event_overflow()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97961"
    },
    {
      "rank": 502,
      "cve_id": "CVE-2026-97962",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/mlx5e: Move representor vnic reporter to eswitch devlink port",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97962"
    },
    {
      "rank": 503,
      "cve_id": "CVE-2026-97963",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: stmmac: initialize ptp_lock at probe time",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97963"
    },
    {
      "rank": 504,
      "cve_id": "CVE-2026-97964",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ppp_synctty: ensure a writeable skb header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97964"
    },
    {
      "rank": 505,
      "cve_id": "CVE-2026-97965",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "vxlan: initialize _md in vxlan_xmit_one()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97965"
    },
    {
      "rank": 506,
      "cve_id": "CVE-2026-97966",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "octeontx2-pf: reset HTB scheduler topology before freeing queues",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97966"
    },
    {
      "rank": 507,
      "cve_id": "CVE-2026-97967",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "hwmon: (corsair-cpro) Remove debugfs entries when probe fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97967"
    },
    {
      "rank": 508,
      "cve_id": "CVE-2026-97968",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "hwmon: (corsair-cpro) Create debugfs entries after hwmon registration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97968"
    },
    {
      "rank": 509,
      "cve_id": "CVE-2026-97969",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "watchdog: msc313e: Fix clock leak and spurious timer in settimeout()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97969"
    },
    {
      "rank": 510,
      "cve_id": "CVE-2026-97970",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "watchdog: msc313e: Avoid division by zero",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97970"
    },
    {
      "rank": 511,
      "cve_id": "CVE-2026-97972",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: macb: put the \"mdio\" child node reference on success",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97972"
    },
    {
      "rank": 512,
      "cve_id": "CVE-2026-97973",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: macb: destroy the phylink instance on the probe error path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97973"
    },
    {
      "rank": 513,
      "cve_id": "CVE-2026-97974",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipv6: null-check fib6_node before accessing in __ip6_del_rt_siblings()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97974"
    },
    {
      "rank": 514,
      "cve_id": "CVE-2026-97975",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: hci_sysfs: Fix NULL pointer dereference in device_del()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97975"
    },
    {
      "rank": 515,
      "cve_id": "CVE-2026-97976",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: btintel_pcie: validate packet_len before skb_put_data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97976"
    },
    {
      "rank": 516,
      "cve_id": "CVE-2026-97977",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: btusb: Fix UAF of btusb_data by rx_work",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97977"
    },
    {
      "rank": 517,
      "cve_id": "CVE-2026-97978",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "eth: ice: don't dereference pointers from TP_printk()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97978"
    },
    {
      "rank": 518,
      "cve_id": "CVE-2026-97979",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ice: add missing xa_destroy for sched_node_ids",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97979"
    },
    {
      "rank": 519,
      "cve_id": "CVE-2026-97980",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "s390/debug: Fix NULL pointer dereference in debug_set_level()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97980"
    },
    {
      "rank": 520,
      "cve_id": "CVE-2026-97981",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: ethernet: cortina: Count dropped frames as NAPI work",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97981"
    },
    {
      "rank": 521,
      "cve_id": "CVE-2026-97982",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: ethernet: cortina: Fix budget accounting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97982"
    },
    {
      "rank": 522,
      "cve_id": "CVE-2026-97983",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "vduse: return compat ioctl results directly",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97983"
    },
    {
      "rank": 523,
      "cve_id": "CVE-2026-97984",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: ipv6: Fix UDP length overflow with PMTU discover and big MTU",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97984"
    },
    {
      "rank": 524,
      "cve_id": "CVE-2026-97985",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "af_unix: Update last skb marker in manage_oob().",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97985"
    },
    {
      "rank": 525,
      "cve_id": "CVE-2026-97986",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "virtio_input: stop callbacks before unregistering input device",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97986"
    },
    {
      "rank": 526,
      "cve_id": "CVE-2026-97987",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "virtio_input: reset device if input_register_device() fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97987"
    },
    {
      "rank": 527,
      "cve_id": "CVE-2026-97988",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "vhost: invalidate vring access on IOTLB transitions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97988"
    },
    {
      "rank": 528,
      "cve_id": "CVE-2026-97989",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "vduse: validate virtqueue alignment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97989"
    },
    {
      "rank": 529,
      "cve_id": "CVE-2026-97992",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "vhost-vdpa: protect config_ctx from being freed under the config callback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97992"
    },
    {
      "rank": 530,
      "cve_id": "CVE-2026-97993",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "vhost-vdpa: don't install the eventfd_ctx_fdget() error in config_ctx",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97993"
    },
    {
      "rank": 531,
      "cve_id": "CVE-2026-97994",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "vhost/vdpa: reject VRING_NUM larger than device max",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97994"
    },
    {
      "rank": 532,
      "cve_id": "CVE-2026-97995",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "virtio_console: do not free control-out buffers on remove",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97995"
    },
    {
      "rank": 533,
      "cve_id": "CVE-2026-97996",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "virtio: fix use-after-free in unregister_virtio_device()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97996"
    },
    {
      "rank": 534,
      "cve_id": "CVE-2026-97997",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "virtio_ring: fix stale descriptor flags after a failed packed add",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97997"
    },
    {
      "rank": 535,
      "cve_id": "CVE-2026-97998",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfilter: nfnetlink_log: cope with concurrent instance destruction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97998"
    },
    {
      "rank": 536,
      "cve_id": "CVE-2026-98000",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "hwmon: Fix potential UAF in pec_store",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98000"
    },
    {
      "rank": 537,
      "cve_id": "CVE-2026-98001",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "hwmon: (ltc4282) Make sure clk_init_data is fully initialized",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98001"
    },
    {
      "rank": 538,
      "cve_id": "CVE-2026-98003",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iommu/amd: Do not reallocate GA log buffers on resume",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98003"
    },
    {
      "rank": 539,
      "cve_id": "CVE-2026-98004",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iommu/riscv: Serialize command queue publishing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98004"
    },
    {
      "rank": 540,
      "cve_id": "CVE-2026-98005",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "erofs: delimit inode_share cache key components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98005"
    },
    {
      "rank": 541,
      "cve_id": "CVE-2026-98006",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: caiaq: Decoupling ep1_in_urb in caiaq dev",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98006"
    },
    {
      "rank": 542,
      "cve_id": "CVE-2026-98007",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Reject non-scalar bpf_loop iteration counts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98007"
    },
    {
      "rank": 543,
      "cve_id": "CVE-2026-98008",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: macb: fix NULL pointer dereference on unbind with fixed-link",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98008"
    },
    {
      "rank": 544,
      "cve_id": "CVE-2026-98009",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/sched: ets: clamp quantum in parse and fallback paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98009"
    },
    {
      "rank": 545,
      "cve_id": "CVE-2026-98010",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/sched: drr: clamp quantum in change class",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98010"
    },
    {
      "rank": 546,
      "cve_id": "CVE-2026-98011",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/sched: hhf: clamp quantum in change and init paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98011"
    },
    {
      "rank": 547,
      "cve_id": "CVE-2026-98012",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/sched: sfq: clamp quantum in change path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98012"
    },
    {
      "rank": 548,
      "cve_id": "CVE-2026-98013",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/sched: fq_pie: clamp quantum in change path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98013"
    },
    {
      "rank": 549,
      "cve_id": "CVE-2026-98014",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/mlx5: E-Switch, prevent mc_list repopulation during vport disable",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98014"
    },
    {
      "rank": 550,
      "cve_id": "CVE-2026-98015",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/mlx5: E-Switch: fix use-after-free in mlx5_eswitch_termtbl_put",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98015"
    },
    {
      "rank": 551,
      "cve_id": "CVE-2026-98016",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/mlx5e: Fix use-after-free race in sample_restore_put()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98016"
    },
    {
      "rank": 552,
      "cve_id": "CVE-2026-98018",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: mctp: i3c: serialize probe with bus removal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98018"
    },
    {
      "rank": 553,
      "cve_id": "CVE-2026-98019",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: mark a NULL call argument precise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98019"
    },
    {
      "rank": 554,
      "cve_id": "CVE-2026-98020",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "pds_core: fix cmd_regs access racing BAR unmap on reset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98020"
    },
    {
      "rank": 555,
      "cve_id": "CVE-2026-98021",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: reject oversized tx_queue_len at netlink parse time",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98021"
    },
    {
      "rank": 556,
      "cve_id": "CVE-2026-98022",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: cap tx_queue_len at S16_MAX to prevent oversized ring allocations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98022"
    },
    {
      "rank": 557,
      "cve_id": "CVE-2026-98024",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "s390/ism: folio_put() after error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98024"
    },
    {
      "rank": 558,
      "cve_id": "CVE-2026-98025",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: usb: cx82310_eth: drop URB after 0xffff reboot sentinel to prevent partial_data heap overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98025"
    },
    {
      "rank": 559,
      "cve_id": "CVE-2026-98026",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: bridge: mcast: properly convert mglist to rcu",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98026"
    },
    {
      "rank": 560,
      "cve_id": "CVE-2026-98028",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "eth: nfp: drop the replaced rule from the list when reprogramming fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98028"
    },
    {
      "rank": 561,
      "cve_id": "CVE-2026-98031",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nexthop: Initialize extack in remove_nh_grp_entry()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98031"
    },
    {
      "rank": 562,
      "cve_id": "CVE-2026-98032",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tracing: Fix subbuf resize races with trace_pipe_raw readers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98032"
    },
    {
      "rank": 563,
      "cve_id": "CVE-2026-98033",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Preserve inner map identity in callback frames",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98033"
    },
    {
      "rank": 564,
      "cve_id": "CVE-2026-98034",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Mark NULL kptr stores precise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98034"
    },
    {
      "rank": 565,
      "cve_id": "CVE-2026-98035",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Cancel special fields when recycling rhtab elements",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98035"
    },
    {
      "rank": 566,
      "cve_id": "CVE-2026-98036",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Preserve special fields in recycled rhtab elements",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98036"
    },
    {
      "rank": 567,
      "cve_id": "CVE-2026-98037",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Reject untrusted allocated-object pointers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98037"
    },
    {
      "rank": 568,
      "cve_id": "CVE-2026-98038",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Keep refcount_acquire nullable for borrowed RCU kptrs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98038"
    },
    {
      "rank": 569,
      "cve_id": "CVE-2026-98039",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Require MEM_PERCPU for percpu kptr stores",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98039"
    },
    {
      "rank": 570,
      "cve_id": "CVE-2026-98040",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Mark the zero register precise for a register-form NULL check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98040"
    },
    {
      "rank": 571,
      "cve_id": "CVE-2026-98042",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Don't resurrect a scalar id dropped by collect_linked_regs()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98042"
    },
    {
      "rank": 572,
      "cve_id": "CVE-2026-98043",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Don't infer non-NULL from a pointer with an unbounded offset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98043"
    },
    {
      "rank": 573,
      "cve_id": "CVE-2026-98044",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Reject legacy packet loads from callbacks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98044"
    },
    {
      "rank": 574,
      "cve_id": "CVE-2026-98045",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Mark faultable stack helpers as sleepable",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98045"
    },
    {
      "rank": 575,
      "cve_id": "CVE-2026-98046",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Mark bpf_btf_find_by_name_kind() as sleepable",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98046"
    },
    {
      "rank": 576,
      "cve_id": "CVE-2026-98047",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Check ancestor frames for rbtree callbacks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98047"
    },
    {
      "rank": 577,
      "cve_id": "CVE-2026-98048",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: don't rewrite bpf_fastcall patterns entered by a jump",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98048"
    },
    {
      "rank": 578,
      "cve_id": "CVE-2026-98049",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: zero extend the result of an arena 32-bit cmpxchg",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98049"
    },
    {
      "rank": 579,
      "cve_id": "CVE-2026-98051",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: bcmasp: fix tx_spb_ring_full() checking same slot cnt times",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98051"
    },
    {
      "rank": 580,
      "cve_id": "CVE-2026-98053",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ASoC: Intel: avs: Refactor and fix init_config access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98053"
    },
    {
      "rank": 581,
      "cve_id": "CVE-2026-98054",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ASoC: Intel: avs: Fix unbalanced module reference count",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98054"
    },
    {
      "rank": 582,
      "cve_id": "CVE-2026-98055",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ASoC: Intel: avs: Clean up the bus when fetching ML caps fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98055"
    },
    {
      "rank": 583,
      "cve_id": "CVE-2026-98057",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ring-buffer: Add checking nr_subbufs to persistent ring buffer validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98057"
    },
    {
      "rank": 584,
      "cve_id": "CVE-2026-98058",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Mark syscall helpers as sleepable",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98058"
    },
    {
      "rank": 585,
      "cve_id": "CVE-2026-98059",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Mark sched_process_wait argument as nullable",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98059"
    },
    {
      "rank": 586,
      "cve_id": "CVE-2026-98060",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Reject resilient lock operations in rbtree callbacks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98060"
    },
    {
      "rank": 587,
      "cve_id": "CVE-2026-98061",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Reject tail calls directly from callback frames",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98061"
    },
    {
      "rank": 588,
      "cve_id": "CVE-2026-98062",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Mark signal tracepoint siginfo arguments as scalar",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98062"
    },
    {
      "rank": 589,
      "cve_id": "CVE-2026-98063",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Fix NULL-ptr-deref in btf_var_show()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98063"
    },
    {
      "rank": 590,
      "cve_id": "CVE-2026-98064",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Fix NULL-ptr-deref when showing a void BTF type",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98064"
    },
    {
      "rank": 591,
      "cve_id": "CVE-2026-98065",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Reject key-less BTF for hash maps",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98065"
    },
    {
      "rank": 592,
      "cve_id": "CVE-2026-98066",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: caiaq: Fix potential double-free at error path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98066"
    },
    {
      "rank": 593,
      "cve_id": "CVE-2026-98067",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "erofs: disable LZ4 rolling decompression for now",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98067"
    },
    {
      "rank": 594,
      "cve_id": "CVE-2026-98068",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/rds: don't let rds_conn_shutdown() consume a concurrent drop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98068"
    },
    {
      "rank": 595,
      "cve_id": "CVE-2026-98071",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/rds: clear cp_flags bits individually in rds_conn_path_reset()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98071"
    },
    {
      "rank": 596,
      "cve_id": "CVE-2026-98072",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/rds: use wq_has_sleeper() in release_in_xmit()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98072"
    },
    {
      "rank": 597,
      "cve_id": "CVE-2026-98074",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bonding: do not clear curr_active_slave prematurely when releasing all slaves",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98074"
    },
    {
      "rank": 598,
      "cve_id": "CVE-2026-98075",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: reject BPF_PSEUDO_FUNC reference to the main program",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98075"
    },
    {
      "rank": 599,
      "cve_id": "CVE-2026-98076",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tracing/probes: Fix use-after-free on field name/type of events with multiple probes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98076"
    },
    {
      "rank": 600,
      "cve_id": "CVE-2026-98077",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfilter: nf_conntrack_sip: fix OOB read in sip_skip_whitespace()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98077"
    },
    {
      "rank": 601,
      "cve_id": "CVE-2026-98078",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipvs: fix reversed sequence option serialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98078"
    },
    {
      "rank": 602,
      "cve_id": "CVE-2026-98079",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "btrfs: zstd: fix lost wakeup when waiting for a workspace",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98079"
    },
    {
      "rank": 603,
      "cve_id": "CVE-2026-98080",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "btrfs: do not force reloc root creation during qgroup_account_snapshot()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98080"
    },
    {
      "rank": 604,
      "cve_id": "CVE-2026-98081",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "btrfs: zoned: finish active block group cleanup if call_zone_finish() fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98081"
    },
    {
      "rank": 605,
      "cve_id": "CVE-2026-98082",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "btrfs: fix the possible bioc_list memory leak during error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98082"
    },
    {
      "rank": 606,
      "cve_id": "CVE-2026-98084",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: backtracking shouldn't clear outer frame R1-R5 for callbacks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98084"
    },
    {
      "rank": 607,
      "cve_id": "CVE-2026-98085",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: backtrack_insn(): Handle ld_{abs,ind} subprog exit edge",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98085"
    },
    {
      "rank": 608,
      "cve_id": "CVE-2026-98086",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: ump: do not touch legacy_rmidi before it exists",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98086"
    },
    {
      "rank": 609,
      "cve_id": "CVE-2026-98087",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "sched/rt,dl: Skip migrate-disabled tasks when picking a push candidate",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98087"
    },
    {
      "rank": 610,
      "cve_id": "CVE-2026-98088",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: mpt3sas: Avoid out-of-bounds cpumask_of_node() call in _base_assign_reply_queues()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98088"
    },
    {
      "rank": 611,
      "cve_id": "CVE-2026-98089",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bonding: alb: fix uninitialized transport header access in alb_determine_nd()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98089"
    },
    {
      "rank": 612,
      "cve_id": "CVE-2026-98090",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "btrfs: restore active device pointers after failed sprout",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98090"
    },
    {
      "rank": 613,
      "cve_id": "CVE-2026-98091",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "btrfs: detach failed sprout device from transaction update list",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98091"
    },
    {
      "rank": 614,
      "cve_id": "CVE-2026-98092",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ASoC: amd: yc: fix memory leak in acp6x_pdm_dma_close()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98092"
    },
    {
      "rank": 615,
      "cve_id": "CVE-2026-98093",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ASoC: fsl_micfil: balance mclk enable/disable",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98093"
    },
    {
      "rank": 616,
      "cve_id": "CVE-2026-98094",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "staging: fbtft: make dirty_lock IRQ-safe",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98094"
    },
    {
      "rank": 617,
      "cve_id": "CVE-2026-98095",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "af_packet: Don't cast tpacket_hdr.tp_len to int in tpacket_parse_header().",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98095"
    },
    {
      "rank": 618,
      "cve_id": "CVE-2026-98097",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tipc: Dont send random pad bytes in RESET/ACTIVATE messages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98097"
    },
    {
      "rank": 619,
      "cve_id": "CVE-2026-98098",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tipc: fix NULL deref in tipc_named_node_up() on empty publication list",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98098"
    },
    {
      "rank": 620,
      "cve_id": "CVE-2026-98099",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipv6: mcast: use rcu_assign_pointer() for __rcu list updates",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98099"
    },
    {
      "rank": 621,
      "cve_id": "CVE-2026-98101",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipv6: mcast: use copy-on-write RCU updates in ip6_mc_source()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98101"
    },
    {
      "rank": 622,
      "cve_id": "CVE-2026-98102",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipv6: mcast: fix RCU list diversion in ip6_mc_del1_src()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98102"
    },
    {
      "rank": 623,
      "cve_id": "CVE-2026-98103",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "igmp: convert struct ip_sf_list to RCU",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98103"
    },
    {
      "rank": 624,
      "cve_id": "CVE-2026-98104",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/sched: cls_u32: fix duplicate handle when node ID pool is exhausted",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98104"
    },
    {
      "rank": 625,
      "cve_id": "CVE-2026-98105",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: ethernet: oa_tc6: Improve the error recovery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98105"
    },
    {
      "rank": 626,
      "cve_id": "CVE-2026-98106",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/pagemap: Prevent double migration of device pages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98106"
    },
    {
      "rank": 627,
      "cve_id": "CVE-2026-98107",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: L2CAP: fix out-of-bounds write in l2cap_ecred_connect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98107"
    },
    {
      "rank": 628,
      "cve_id": "CVE-2026-98109",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: hci_core: Fix race condition during device registration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98109"
    },
    {
      "rank": 629,
      "cve_id": "CVE-2026-98110",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: btintel: bound firmware ID by TLV length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98110"
    },
    {
      "rank": 630,
      "cve_id": "CVE-2026-98111",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: btintel: validate version TLV value lengths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98111"
    },
    {
      "rank": 631,
      "cve_id": "CVE-2026-98113",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ksmbd: rate limit unmapped SID errors",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98113"
    },
    {
      "rank": 632,
      "cve_id": "CVE-2026-98114",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ksmbd: propagate DACL parsing errors",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98114"
    },
    {
      "rank": 633,
      "cve_id": "CVE-2026-98117",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "cachefiles: Fix potential UAF/KASAN warning",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98117"
    },
    {
      "rank": 634,
      "cve_id": "CVE-2026-98118",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfs: Fix readahead synchronisation issues by loading all folios upfront",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98118"
    },
    {
      "rank": 635,
      "cve_id": "CVE-2026-98119",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfs: break unbuffered write when netfs_alloc_subrequest() fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98119"
    },
    {
      "rank": 636,
      "cve_id": "CVE-2026-98120",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfs: Fix subreq ref leak",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98120"
    },
    {
      "rank": 637,
      "cve_id": "CVE-2026-98121",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "watchdog: msc313e: Fix NULL pointer dereference in PM callbacks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98121"
    },
    {
      "rank": 638,
      "cve_id": "CVE-2026-98123",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "sctp: fix soft lockup from unpadded ASCONF-ACK parameter iteration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98123"
    },
    {
      "rank": 639,
      "cve_id": "CVE-2026-98124",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb/client: invalidate fscache for fallocate range operations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98124"
    },
    {
      "rank": 640,
      "cve_id": "CVE-2026-98125",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb/client: fix stale page cache in insert/collapse range",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98125"
    },
    {
      "rank": 641,
      "cve_id": "CVE-2026-98126",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb/client: validate new EOF for zero range",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98126"
    },
    {
      "rank": 642,
      "cve_id": "CVE-2026-98127",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb/client: validate new EOF for insert range",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98127"
    },
    {
      "rank": 643,
      "cve_id": "CVE-2026-98128",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: mpi3mr: Fix target device refcount leak in mpi3mr_sas_port_add()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98128"
    },
    {
      "rank": 644,
      "cve_id": "CVE-2026-98129",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: mpi3mr: Fix NULL pointer dereference in mpi3mr_sas_port_add()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98129"
    },
    {
      "rank": 645,
      "cve_id": "CVE-2026-98131",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: stmmac: fix dma mapping leak in stmmac_tso_xmit()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98131"
    },
    {
      "rank": 646,
      "cve_id": "CVE-2026-98132",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: don't downgrade half-dead scalar zero spills to STACK_ZERO",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98132"
    },
    {
      "rank": 647,
      "cve_id": "CVE-2026-98133",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ntfs: leave HasEA flag untouched on setxattr failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98133"
    },
    {
      "rank": 648,
      "cve_id": "CVE-2026-98134",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: check_cond_jmp_op(): properly infer if register is null",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98134"
    },
    {
      "rank": 649,
      "cve_id": "CVE-2026-98135",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ntfs: reject invalid sectors_per_cluster in the boot sector",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98135"
    },
    {
      "rank": 650,
      "cve_id": "CVE-2026-98136",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ntfs: bound $AttrDef table walk to the loaded table size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98136"
    },
    {
      "rank": 651,
      "cve_id": "CVE-2026-98137",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ntfs: treat any nonzero dio zero-range return as an error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98137"
    },
    {
      "rank": 652,
      "cve_id": "CVE-2026-98138",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ntfs: do not mark the volume clean in sync_fs when errors were recorded",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98138"
    },
    {
      "rank": 653,
      "cve_id": "CVE-2026-98139",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ntfs: only count successfully cleared runs when freeing clusters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98139"
    },
    {
      "rank": 654,
      "cve_id": "CVE-2026-98140",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ntfs: fix kmap_local leak in write_mft_record_nolock() error paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98140"
    },
    {
      "rank": 655,
      "cve_id": "CVE-2026-98141",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ntfs: propagate reparse index insertion failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98141"
    },
    {
      "rank": 656,
      "cve_id": "CVE-2026-98142",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/cirrus-qemu: Validate BAR0 size during probe",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98142"
    },
    {
      "rank": 657,
      "cve_id": "CVE-2026-98144",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "accel/amdxdna: put the chained BO when its mapping fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98144"
    },
    {
      "rank": 658,
      "cve_id": "CVE-2026-98145",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "accel/amdxdna: reject a command chain that carries no commands",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98145"
    },
    {
      "rank": 659,
      "cve_id": "CVE-2026-98146",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "accel/amdxdna: Remove __counted_by from struct amdxdna_cmd_chain",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98146"
    },
    {
      "rank": 660,
      "cve_id": "CVE-2026-98147",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "printk: Don't WARN on kthread_run failure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98147"
    },
    {
      "rank": 661,
      "cve_id": "CVE-2026-98148",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/gud: validate GUD_ROTATION_0 is present in supported rotations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98148"
    },
    {
      "rank": 662,
      "cve_id": "CVE-2026-98149",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Fix percpu map update indexing with sparse CPU IDs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98149"
    },
    {
      "rank": 663,
      "cve_id": "CVE-2026-98151",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Fix REG INVARIANTS VIOLATION on speculative pointer arithmetic",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98151"
    },
    {
      "rank": 664,
      "cve_id": "CVE-2026-98152",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nvmet-rdma: fix queue leak when connect backlog is exceeded",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98152"
    },
    {
      "rank": 665,
      "cve_id": "CVE-2026-98153",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nvme: fix racy access to FDP placement id array",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98153"
    },
    {
      "rank": 666,
      "cve_id": "CVE-2026-98155",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "accel/qaic: Address potential out-of-bounds read in resp_worker()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98155"
    },
    {
      "rank": 667,
      "cve_id": "CVE-2026-98157",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "EDAC/device_sysfs: Use kstrtouint() for poll_msec to prevent truncation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98157"
    },
    {
      "rank": 668,
      "cve_id": "CVE-2026-98158",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ppp_async: drop the errored frame instead of resetting its headroom",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98158"
    },
    {
      "rank": 669,
      "cve_id": "CVE-2026-98159",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mt76: mt7921: validate CLC firmware records",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98159"
    },
    {
      "rank": 670,
      "cve_id": "CVE-2026-98160",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "staging: rtl8723bs: fix mismatched free of HalData in rtw_sdio_if1_init()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98160"
    },
    {
      "rank": 671,
      "cve_id": "CVE-2026-98161",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nvdimm: pmem: keep PREFLUSH before data writes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98161"
    },
    {
      "rank": 672,
      "cve_id": "CVE-2026-98162",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb/server: fix tree connection leak in smb2_tree_connect()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98162"
    },
    {
      "rank": 673,
      "cve_id": "CVE-2026-100070",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfilter: nf_nat_sip: rewind offset when NAT shrinks the packet",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100070"
    },
    {
      "rank": 674,
      "cve_id": "CVE-2026-100071",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: hsr: free learned nodes on device setup failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100071"
    },
    {
      "rank": 675,
      "cve_id": "CVE-2026-100072",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ACPI: platform: Use acpi_bus_get_primary_device()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100072"
    },
    {
      "rank": 676,
      "cve_id": "CVE-2026-100073",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ext4: fix transaction overflow during writeback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100073"
    },
    {
      "rank": 677,
      "cve_id": "CVE-2026-100074",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Mark bpf_refcount field as unique",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100074"
    },
    {
      "rank": 678,
      "cve_id": "CVE-2026-100076",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "staging: rtl8723bs: fix xmit_frame/xmit_buf leaks on mgnt-frame error paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100076"
    },
    {
      "rank": 679,
      "cve_id": "CVE-2026-100077",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/msm: Recover HW before retire hung submit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100077"
    },
    {
      "rank": 680,
      "cve_id": "CVE-2026-100078",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: iwlwifi: mei: pass correct argument to function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100078"
    },
    {
      "rank": 681,
      "cve_id": "CVE-2026-100079",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: typec: ucsi: unregister debugfs entries on teardown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100079"
    }
  ],
  "transactions": [
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-65660",
      "detail": "ADDED TO KEV — CVE-2026-65660 (Microsoft SharePoint Enterprise Server 2016). Remediation due September 28, 2026."
    },
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-67279",
      "detail": "ADDED TO KEV — CVE-2026-67279 (Mikrotik RouterOS). Remediation due September 28, 2026."
    },
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-87902",
      "detail": "ADDED TO KEV — CVE-2026-87902 (WordPress). Remediation due September 28, 2026."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-2604",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-2604 (GNOME Evolution Data Server). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-43642",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-43642 (Softaculous Virtualizor). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67276",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67276 (Mikrotik RouterOS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67278",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67278 (Mikrotik RouterOS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67279",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67279 (Mikrotik RouterOS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67281",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67281 (Mikrotik RouterOS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73241",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73241 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73242",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73242 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-77252",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-77252 (sooperset mcp-atlassian). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-77261",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-77261 (sooperset mcp-atlassian). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-81878",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-81878 (radareorg radare2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-81879",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-81879 (radareorg radare2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-81881",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-81881 (radareorg radare2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-81882",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-81882 (radareorg radare2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-85724",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-85724 (moquette-io moquette). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-89078",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-89078 (GitLab). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-93339",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-93339 (Metaphor Creations Ditty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-93353",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-93353 (9001 copyparty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-93577",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-93577 (GitLab). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-95396",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-95396 (sfturing hosp_order). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-95657",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-95657 (dgtlmoon Changedetection.io). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-95811",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-95811 (Lemonldap-NG-Handler). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-95842",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-95842 (moquette-io moquette). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-95843",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-95843 (moquette-io moquette). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-95845",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-95845 (moquette-io moquette). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-95846",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-95846 (moquette-io moquette). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-95924",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-95924 (SourceCodester Online Reviewer Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-96258",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-96258 (onSite internet GmbH Auktion NG Auktionssoftware). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-96272",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-96272 (MacWarrior clipbucket-v5). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-97326",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-97326 (songxinjianqwe Chat). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-97366",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-97366 (jhen0409 react-native-debugger). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-97368",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-97368 (chillzhuang SpringBlade). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-7273",
      "detail": "DUE DATE PASSED — CVE-2026-7273 (Zyxel GS1900-48HPv2 firmware). CISA remediation deadline was September 24, 2026; still in catalog."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-0857",
      "detail": "RESCORED — CVE-2026-0857 (Mesalvo Meona Client). CVSS 6 → 4.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-22314",
      "detail": "RESCORED — CVE-2026-22314 (Mesalvo Meona Client Launcher Component). CVSS 9 → 7.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-25602",
      "detail": "RESCORED — CVE-2026-25602 (Mesalvo Meona Server). CVSS 4.4 → 2.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-48411",
      "detail": "RESCORED — CVE-2026-48411 (Adobe Commerce). CVSS 6.5 → 4.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-48412",
      "detail": "RESCORED — CVE-2026-48412 (Adobe Commerce). CVSS 2.7 → 7.2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-48414",
      "detail": "RESCORED — CVE-2026-48414 (Adobe Commerce). CVSS 7.7 → 8.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-48415",
      "detail": "RESCORED — CVE-2026-48415 (Adobe Commerce). CVSS 7.6 → 8.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-55946",
      "detail": "RESCORED — CVE-2026-55946 (Microsoft Copilot). CVSS 6.1 → 5.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-68791",
      "detail": "RESCORED — CVE-2026-68791 (Microsoft Azure Machine Learning). CVSS 8.6 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-69399",
      "detail": "RESCORED — CVE-2026-69399 (Microsoft Azure ARC). CVSS 10 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-70009",
      "detail": "RESCORED — CVE-2026-70009 (Microsoft Azure ARC). CVSS 9.3 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-70200",
      "detail": "RESCORED — CVE-2026-70200 (Microsoft Azure Logic Apps). CVSS 10 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-77261",
      "detail": "RESCORED — CVE-2026-77261 (sooperset mcp-atlassian). CVSS 7.1 → 8.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-77903",
      "detail": "RESCORED — CVE-2026-77903 (Microsoft Dataverse). CVSS 9 → 8.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-78510",
      "detail": "RESCORED — CVE-2026-78510 (Microsoft 365 Apps for Enterprise). CVSS 9.8 → 8.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-81879",
      "detail": "RESCORED — CVE-2026-81879 (radareorg radare2). CVSS 5.5 → 6.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-81881",
      "detail": "RESCORED — CVE-2026-81881 (radareorg radare2). CVSS 3.3 → 4.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-81882",
      "detail": "RESCORED — CVE-2026-81882 (radareorg radare2). CVSS 3.3 → 6.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-83944",
      "detail": "RESCORED — CVE-2026-83944 (Microsoft Azure Logic Apps). CVSS 10 → 9.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-83946",
      "detail": "RESCORED — CVE-2026-83946 (Microsoft Azure Portal). CVSS 8.2 → 6.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-83964",
      "detail": "RESCORED — CVE-2026-83964 (Adobe Connect). CVSS 6.2 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-85885",
      "detail": "RESCORED — CVE-2026-85885 (Microsoft 365 Copilot). CVSS 9.9 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-85889",
      "detail": "RESCORED — CVE-2026-85889 (Microsoft Azure AI Foundry). CVSS 10 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-90902",
      "detail": "RESCORED — CVE-2026-90902 (joomshaper.com Easy Store extension for Joomla). CVSS 8.2 → 8.6 (NVD)."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2026-22315",
      "detail": "REJECTED — CVE-2026-22315 (Mesalvo Meona Client Launcher Component). Record withdrawn by the CNA."
    },
    {
      "type": "DISPUTED",
      "cve_id": "CVE-2026-22314",
      "detail": "DISPUTED — CVE-2026-22314 (Mesalvo Meona Client Launcher Component). Record marked disputed."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-88264",
      "detail": "PATCH SHIPPED — CVE-2026-88264 (containers crun). Fixed in Red Hat Hardened Images 1.30-1.hum1."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-88831",
      "detail": "PATCH SHIPPED — CVE-2026-88831 (Red Hat Hardened Images). Fixed in Red Hat Hardened Images 1.37.0-9.1.hum1."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-88832",
      "detail": "PATCH SHIPPED — CVE-2026-88832 (Red Hat Hardened Images). Fixed in Red Hat Hardened Images 1.37.0-9.1.hum1."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-88835",
      "detail": "PATCH SHIPPED — CVE-2026-88835 (Red Hat Hardened Images). Fixed in Red Hat Hardened Images 1.37.0-9.1.hum1."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-88837",
      "detail": "PATCH SHIPPED — CVE-2026-88837 (Red Hat Hardened Images). Fixed in Red Hat Hardened Images 1.37.0-9.1.hum1."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-88839",
      "detail": "PATCH SHIPPED — CVE-2026-88839 (Red Hat Hardened Images). Fixed in Red Hat Hardened Images 1.37.0-9.1.hum1."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
