{
  "day": "2026-09-28",
  "boundary": "UTC calendar day",
  "published_count": 314,
  "by_severity": {
    "CRITICAL": 32,
    "HIGH": 98,
    "MEDIUM": 136,
    "LOW": 38
  },
  "kev_count": 0,
  "exploit_reference_count": 10,
  "awaiting_enrichment_count": 10,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-101001",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02635,
      "epss_percentile": 0.84964,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netcore",
      "product": "NBR200V2",
      "cwe": "CWE-77",
      "title": "Netcore NBR200V2 Web Management network_tools eval os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101001"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-101008",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.02336,
      "epss_percentile": 0.82914,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aaPanel",
      "product": "BaoTa",
      "cwe": "CWE-74",
      "title": "aaPanel BaoTa File Merge files.py merge_split_file command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101008"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-100896",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.01864,
      "epss_percentile": 0.78431,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TOTOLINK",
      "product": "N150RT",
      "cwe": "CWE-77",
      "title": "TOTOLINK N150RT Web Management formWlSiteSurvey system os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100896"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-101007",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.01764,
      "epss_percentile": 0.77152,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aaPanel",
      "product": "BaoTa",
      "cwe": "CWE-77",
      "title": "aaPanel BaoTa Database Backup database.py InputSql os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101007"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-101009",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.01764,
      "epss_percentile": 0.77152,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aaPanel",
      "product": "BaoTa",
      "cwe": "CWE-77",
      "title": "aaPanel BaoTa Unzip panelTask.py panelTask.bt_task._unzip os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101009"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-101002",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0167,
      "epss_percentile": 0.7586,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netcore",
      "product": "NBR200V2",
      "cwe": "CWE-77",
      "title": "Netcore NBR200V2 Tools Ping network_tools system os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101002"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-101037",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00805,
      "epss_percentile": 0.55047,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FAST",
      "product": "FAC1200R",
      "cwe": "CWE-119",
      "title": "FAST FAC1200R devdiscover Service parse_advertisement_frame stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101037"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-100908",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00802,
      "epss_percentile": 0.54907,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Eyeplus",
      "cwe": "CWE-119",
      "title": "Eyeplus p2pcam HTTP stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100908"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-82384",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00768,
      "epss_percentile": 0.5375,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Roller",
      "cwe": "CWE-502",
      "title": "Apache Roller: Unauthenticated deserialization in the XML-RPC endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82384"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-100895",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00671,
      "epss_percentile": 0.50074,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Trusted Domain Project",
      "product": "OpenARC",
      "cwe": "CWE-404",
      "title": "Trusted Domain Project OpenARC libopenarc arc-canon.c arc_parse_canon_t null pointer dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100895"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-100892",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0061,
      "epss_percentile": 0.47095,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aligungr",
      "product": "UERANSIM",
      "cwe": "CWE-119",
      "title": "aligungr UERANSIM nr-gnb handler.cpp ULInformationTransfer memory corruption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100892"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-101035",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00538,
      "epss_percentile": 0.43031,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aligungr",
      "product": "UERANSIM",
      "cwe": "CWE-248",
      "title": "aligungr UERANSIM nr-gnb encode.cpp DecodePlainMmMessage uncaught exception",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101035"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-82377",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00535,
      "epss_percentile": 0.429,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Roller",
      "cwe": "CWE-862",
      "title": "Apache Roller: Missing weblog authorization in XML-RPC Blogger/MetaWeblog handlers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82377"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-101000",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00501,
      "epss_percentile": 0.40466,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netcore",
      "product": "NBR100V2",
      "cwe": "CWE-862",
      "title": "Netcore NBR100V2 ACL unauthenticated.json uci.apply authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101000"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-101004",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00497,
      "epss_percentile": 0.40159,
      "kev": false,
      "kev_due_at": null,
      "vendor": "notionnext-org",
      "product": "NotionNext",
      "cwe": "CWE-287",
      "title": "notionnext-org NotionNext Authentication Guard cache.js cleanCache missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101004"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-82383",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00491,
      "epss_percentile": 0.39749,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Roller",
      "cwe": "CWE-306",
      "title": "Apache Roller: Anonymous setup action allows frontpage configuration tampering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82383"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-101003",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00462,
      "epss_percentile": 0.37575,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cesanta",
      "product": "Mongoose",
      "cwe": "CWE-119",
      "title": "Cesanta Mongoose MQTT Broker main.c fn stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101003"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-100903",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00454,
      "epss_percentile": 0.36892,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ООО НПО Ритм",
      "product": "GEOritm",
      "cwe": "CWE-287",
      "title": "ООО НПО Ритм GEOritm REST API obj-groups missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100903"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-100893",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00452,
      "epss_percentile": 0.36768,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Privoce",
      "product": "VoceChat Server",
      "cwe": "CWE-918",
      "title": "Privoce VoceChat Server open_graphic_parse Endpoint resource.rs fetch server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100893"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-82378",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00421,
      "epss_percentile": 0.3392,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Roller",
      "cwe": "CWE-863",
      "title": "Apache Roller: OAuth authorization endpoint trusts request-supplied identity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82378"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-86507",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00396,
      "epss_percentile": 0.31158,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Roller",
      "cwe": "CWE-79",
      "title": "Apache Roller: Stored XSS in comment moderation via comment author URL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86507"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-91204",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00396,
      "epss_percentile": 0.31158,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Roller",
      "cwe": "CWE-79",
      "title": "Apache Roller: Stored javascript: URI in HTML comments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91204"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-91206",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00396,
      "epss_percentile": 0.31158,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Roller",
      "cwe": "CWE-79",
      "title": "Apache Roller: Reflected XSS in the optional LDAP comment authenticator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91206"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-7172",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0039,
      "epss_percentile": 0.30453,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TPVEnlanube",
      "product": "Cloud Web application",
      "cwe": "CWE-79",
      "title": "Stored Cross-Site Scripting (XSS) in TPVEnlanube",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7172"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-82375",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00373,
      "epss_percentile": 0.28715,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Roller",
      "cwe": "CWE-918",
      "title": "Apache Roller: Server-side request forgery via entry trackback and enclosure URLs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82375"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-100890",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00372,
      "epss_percentile": 0.28613,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Trusted Domain Project",
      "product": "OpenDMARC",
      "cwe": "CWE-404",
      "title": "Trusted Domain Project OpenDMARC SPF Parser opendmarc_spf.c opendmarc_spf_ipv6_explode null pointer dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100890"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-82379",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.28339,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Roller",
      "cwe": "CWE-294",
      "title": "Apache Roller: WSSE digest authentication headers can be replayed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82379"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-82348",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00365,
      "epss_percentile": 0.27791,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Roller",
      "cwe": "CWE-639",
      "title": "Apache Roller: Cross-weblog resource tampering via unscoped authoring lookups",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82348"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-86530",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0036,
      "epss_percentile": 0.27282,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BUFFALO INC.",
      "product": "WSR-300HP",
      "cwe": "CWE-78",
      "title": "BUFFALO Wi-Fi products handle some web form input improperly to assemble command line strings internally. An administrative user may send a crafted HTTP request and execute an arbitrary OS command.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86530"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-95104",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00357,
      "epss_percentile": 0.26876,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BUFFALO INC.",
      "product": "WSR-300HP",
      "cwe": "CWE-121",
      "title": "Stack-based buffer overflow vulnerability exists in BUFFALO Wi-Fi products. A non-authenticated crafted HTTP request may cause a denial-of-service (DoS) condition.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95104"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-100902",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00334,
      "epss_percentile": 0.24238,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Barco",
      "product": "ClickShare CX-20 Gen2",
      "cwe": "CWE-20",
      "title": "Barco ClickShare CX-20 Gen2 Wallpaper Upload wallpaper improper validation of syntactic correctness of input",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100902"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-101018",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00332,
      "epss_percentile": 0.23839,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dayrui",
      "product": "XunruiCMS",
      "cwe": "CWE-74",
      "title": "dayrui XunruiCMS Group Editing Home.php group_all_edit sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101018"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-101016",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00324,
      "epss_percentile": 0.23,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Trusted Domain Project",
      "product": "OpenDMARC",
      "cwe": "CWE-755",
      "title": "Trusted Domain Project OpenDMARC opendmarc_policy.c opendmarc_policy_parse_dmarc exceptional condition",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101016"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-101017",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00324,
      "epss_percentile": 0.23001,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Trusted Domain Project",
      "product": "OpenDMARC",
      "cwe": "CWE-755",
      "title": "Trusted Domain Project OpenDMARC opendmarc_policy.c strcasecmp exceptional condition",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101017"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-101014",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00314,
      "epss_percentile": 0.21848,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Trusted Domain Project",
      "product": "OpenDMARC",
      "cwe": "CWE-189",
      "title": "Trusted Domain Project OpenDMARC DMARC Record opendmarc_util.c opendmarc_util_cleanup off-by-one",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101014"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-100751",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00304,
      "epss_percentile": 0.20788,
      "kev": false,
      "kev_due_at": null,
      "vendor": "regularlabs.com",
      "product": "Tabs & Accordions (Free, Pro) extension for Joomla",
      "cwe": "CWE-79",
      "title": "Joomla Extension - regularlabs.com - Privileged stored XSS via data-rlta-url attributes in Tabs & Accordions (Pro) 2.3.0 - 3.1.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100751"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-7170",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00303,
      "epss_percentile": 0.20645,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TPVEnlanube",
      "product": "Cloud Web application",
      "cwe": "CWE-79",
      "title": "Stored Cross-Site Scripting (XSS) in TPVEnlanube",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7170"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-7171",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00303,
      "epss_percentile": 0.20644,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TPVEnlanube",
      "product": "Cloud Web application",
      "cwe": "CWE-79",
      "title": "Stored Cross-Site Scripting (XSS) in TPVEnlanube",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7171"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-100894",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00303,
      "epss_percentile": 0.20669,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mathurvishal",
      "product": "CloudClassroom-PHP-Project",
      "cwe": "CWE-74",
      "title": "mathurvishal CloudClassroom-PHP-Project updateguest.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100894"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-100909",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00298,
      "epss_percentile": 0.20146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "OctoberCMS",
      "cwe": "CWE-918",
      "title": "OctoberCMS ResizeImages.php getSourcePathForResize server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100909"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-101005",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00298,
      "epss_percentile": 0.20145,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "October CMS",
      "cwe": "CWE-918",
      "title": "October CMS SSRF Protection ResizeImages.php validateExternalImageHost server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101005"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-82376",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00296,
      "epss_percentile": 0.20007,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Roller",
      "cwe": "CWE-611",
      "title": "Apache Roller: XML external entity processing in trackback response parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82376"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-82915",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00295,
      "epss_percentile": 0.19922,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bimser Solution Software Trade Inc.",
      "product": "eBA Plus Document and Workflow Management System",
      "cwe": "CWE-22",
      "title": "Path Traversal in Bimser Solution Software's eBA Plus",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82915"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-100891",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00293,
      "epss_percentile": 0.19679,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Trusted Domain Project",
      "product": "OpenDMARC",
      "cwe": "CWE-172",
      "title": "Trusted Domain Project OpenDMARC Internationalized Domain Name opendmarc_policy.c opendmarc_policy_query_dmarc encoding error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100891"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-101015",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00293,
      "epss_percentile": 0.19679,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Trusted Domain Project",
      "product": "OpenDMARC",
      "cwe": "CWE-20",
      "title": "Trusted Domain Project OpenDMARC policy.c improper validation of unsafe equivalence in input",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101015"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-82386",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.19467,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Roller",
      "cwe": "CWE-611",
      "title": "Apache Roller: XML external entity processing in OPML bookmark import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82386"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-100906",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00286,
      "epss_percentile": 0.18969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Eyeplus",
      "cwe": "CWE-200",
      "title": "Eyeplus ONVIF Device GetUsers information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100906"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-100907",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00286,
      "epss_percentile": 0.18969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Eyeplus",
      "cwe": "CWE-200",
      "title": "Eyeplus p2pcam Service snapshot information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100907"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-100901",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00278,
      "epss_percentile": 0.18194,
      "kev": false,
      "kev_due_at": null,
      "vendor": "athlon1600",
      "product": "youtube-downloader",
      "cwe": "CWE-918",
      "title": "athlon1600 youtube-downloader stream.php stream server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100901"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-82380",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00276,
      "epss_percentile": 0.17992,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Roller",
      "cwe": "CWE-352",
      "title": "Apache Roller: CSRF protection bypass via self-generated salt validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82380"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-82385",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00276,
      "epss_percentile": 0.1798,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Roller",
      "cwe": "CWE-200",
      "title": "Apache Roller: Weblog template include escapes the Velocity sandbox and reads classpath files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82385"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-82546",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00276,
      "epss_percentile": 0.17954,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Roller",
      "cwe": "CWE-79",
      "title": "Apache Roller: Stored cross-site scripting through incoming Trackback links",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82546"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-85134",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00266,
      "epss_percentile": 0.16849,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bimser Solution Software Trade Inc.",
      "product": "eBA Plus Document and Workflow Management System",
      "cwe": "CWE-434",
      "title": "Arbitrary File Upload Leading to Remote Command Execution in Bimser's eBA Plus",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85134"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-90979",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00265,
      "epss_percentile": 0.165,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Karaf",
      "cwe": "CWE-90",
      "title": "Apache Karaf: LDAP filter injection in JAAS LDAP login modules",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90979"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-101012",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.15217,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mathurvishal",
      "product": "CloudClassroom-PHP-Project",
      "cwe": "CWE-74",
      "title": "mathurvishal CloudClassroom-PHP-Project makeresult.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101012"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-101013",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.15215,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mathurvishal",
      "product": "CloudClassroom-PHP-Project",
      "cwe": "CWE-74",
      "title": "mathurvishal CloudClassroom-PHP-Project updateresultdetails.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101013"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-82382",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00253,
      "epss_percentile": 0.15125,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Roller",
      "cwe": "CWE-79",
      "title": "Apache Roller: Reflected cross-site scripting in the frontpage directory parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82382"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-101010",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00249,
      "epss_percentile": 0.14526,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aaPanel",
      "product": "BaoTa",
      "cwe": "CWE-74",
      "title": "aaPanel BaoTa data.py getData sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101010"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-100750",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00229,
      "epss_percentile": 0.12342,
      "kev": false,
      "kev_due_at": null,
      "vendor": "regularlabs.com",
      "product": "Modules Anywhere (Pro) extension for Joomla",
      "cwe": "CWE-918",
      "title": "Joomla Extension - regularlabs.com - Arbitrary file read / SSRF in Modules Anywhere 1.5.0 - 9.0.5 for Joomla",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100750"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-86838",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00217,
      "epss_percentile": 0.10865,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Bookly",
      "cwe": "CWE-472",
      "title": "Bookly < 28.3 - Unauthenticated Payment Bypass via Booking Price Manipulation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86838"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-101036",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.0021,
      "epss_percentile": 0.10118,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FLB-Music",
      "product": "FLB-Music-Player",
      "cwe": "CWE-22",
      "title": "FLB-Music FLB-Music-Player createParsedTrack.ts path.join path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101036"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-101006",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00203,
      "epss_percentile": 0.09191,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Frappe",
      "product": "HR",
      "cwe": "CWE-285",
      "title": "Frappe HR Permission Validation __init__.py get_attendance_requests authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101006"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-101011",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00202,
      "epss_percentile": 0.09,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aaPanel",
      "product": "BaoTa",
      "cwe": "CWE-74",
      "title": "aaPanel BaoTa Domain domainMod.py get_domain_status sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101011"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-94283",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00199,
      "epss_percentile": 0.08691,
      "kev": false,
      "kev_due_at": null,
      "vendor": "x.org",
      "product": "libX11",
      "cwe": "CWE-125",
      "title": "Out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94283"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-100898",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00192,
      "epss_percentile": 0.07963,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DevaslanPHP",
      "product": "project-management",
      "cwe": "CWE-74",
      "title": "DevaslanPHP project-management Timesheet Dashboard ActivitiesReport.php whereRaw sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100898"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-100899",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00192,
      "epss_percentile": 0.07964,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DevaslanPHP",
      "product": "project-management",
      "cwe": "CWE-74",
      "title": "DevaslanPHP project-management Timesheet Dashboard MonthlyReport.php whereRaw sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100899"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-100904",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00191,
      "epss_percentile": 0.07832,
      "kev": false,
      "kev_due_at": null,
      "vendor": "amirsanni",
      "product": "mini-inventory-and-sales-management-system",
      "cwe": "CWE-79",
      "title": "amirsanni mini-inventory-and-sales-management-system Items Management Items.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100904"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-94286",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00185,
      "epss_percentile": 0.07193,
      "kev": false,
      "kev_due_at": null,
      "vendor": "x.org",
      "product": "libXtst",
      "cwe": "CWE-126",
      "title": "Out-of-bounds read in libXtst's RECORD reply parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94286"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-84744",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00183,
      "epss_percentile": 0.07048,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WPForms",
      "cwe": "CWE-94",
      "title": "WPForms Lite 1.5.0.1 - 2.0.2 - Unauthenticated Arbitrary Shortcode Execution via Form Field Repopulation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84744"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-82381",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.06914,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Roller",
      "cwe": "CWE-79",
      "title": "Apache Roller: Stored cross-site scripting in the authoring UI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82381"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-82387",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.06914,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Roller",
      "cwe": "CWE-79",
      "title": "Apache Roller: Stored cross-site scripting via uploaded media content type",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82387"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-93000",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00177,
      "epss_percentile": 0.06489,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "SPS-Suite",
      "cwe": "CWE-89",
      "title": "SPS-Suite <= 1.4.0 - Unauthenticated Time-Based SQLi via Search",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93000"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-88828",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00167,
      "epss_percentile": 0.05356,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Blacklist Manager",
      "cwe": "CWE-288",
      "title": "Blacklist Manager for WooCommerce 1.3.0 - 2.3.1 - Blocked User Restriction Bypass via XML-RPC and Application Passwords",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88828"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-100897",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00163,
      "epss_percentile": 0.04876,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fuzui",
      "product": "StudentInfo",
      "cwe": "CWE-285",
      "title": "fuzui StudentInfo Password Change Endpoint moditypasswordstu authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100897"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-89303",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.04763,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Post Voting System",
      "cwe": "CWE-89",
      "title": "Post Voting System <= 1.0 - Subscriber+ SQLi via 'row' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89303"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-100900",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00155,
      "epss_percentile": 0.03948,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DevaslanPHP",
      "product": "project-management",
      "cwe": "CWE-918",
      "title": "DevaslanPHP project-management Jira Import jira-import updateJiraProjects server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100900"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-82969",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00148,
      "epss_percentile": 0.03337,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bimser Solution Software Trade Inc.",
      "product": "eBA Plus Document and Workflow Management System",
      "cwe": "CWE-79",
      "title": "Stored XSS in BİMSER's eBA Plus",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82969"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-89300",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.02521,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Verify API",
      "cwe": "CWE-862",
      "title": "WP Verify API <= 1.0.0 - Unauthenticated Verification Code Email Sending to Arbitrary Recipients",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89300"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-94282",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00131,
      "epss_percentile": 0.0223,
      "kev": false,
      "kev_due_at": null,
      "vendor": "x.org",
      "product": "libXi",
      "cwe": "CWE-125",
      "title": "Out-of-bounds read in libXi's XI2 enter/leave/focus cookie conversion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94282"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-89411",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01356,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Paymattic",
      "cwe": "CWE-345",
      "title": "Paymattic < 4.6.26 - Unauthenticated Payment Bypass via Unbound Stripe PaymentIntent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89411"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-92996",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01356,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Verge3D Publishing and E-Commerce",
      "cwe": "CWE-345",
      "title": "Verge3D 4.1.0 - 4.13.0 - Unauthenticated Payment Bypass via v3d_payment_done",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92996"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-87723",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00113,
      "epss_percentile": 0.01302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "fuse-archive",
      "cwe": "CWE-426",
      "title": "Untrusted Search Path (PATH Hijacking) in fuse-archive",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87723"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-94285",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00111,
      "epss_percentile": 0.01239,
      "kev": false,
      "kev_due_at": null,
      "vendor": "x.org",
      "product": "libX11",
      "cwe": "CWE-125",
      "title": "Out-of-bounds read in libX11's byte-oriented codeset parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94285"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-94284",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00103,
      "epss_percentile": 0.00915,
      "kev": false,
      "kev_due_at": null,
      "vendor": "x.org",
      "product": "libX11",
      "cwe": "CWE-125",
      "title": "Out-of-bounds read vulnerability in libX11's XIM trigger-keyregistration parser.registration parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94284"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-94287",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.001,
      "epss_percentile": 0.00795,
      "kev": false,
      "kev_due_at": null,
      "vendor": "x.org",
      "product": "libXpm",
      "cwe": "CWE-1050",
      "title": "Denial of service via unsigned underflow in libXpm's write path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94287"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-85526",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canonical",
      "product": "LXD",
      "cwe": "CWE-22",
      "title": "Path traversal via Btrfs optimized-backup subvolumes[].path enables root file/dir manipulation in LXD",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85526"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-87799",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canonical",
      "product": "LXD",
      "cwe": "CWE-59",
      "title": "Arbitrary file write on LXD host via symlink in migration stream",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87799"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-90924",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Innotim Software, Telecommunications and Consultancy Trade Ltd. Co.",
      "product": "Logsign SIEM",
      "cwe": "CWE-1392",
      "title": "Default Admin Credentials in Innotim Software's Logsign SIEM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90924"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-12342",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SailPoint Technologies",
      "product": "IdentityIQ",
      "cwe": "CWE-20",
      "title": "SailPoint IdentityIQ Improper Form Validation Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12342"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-85185",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canonical",
      "product": "LXD",
      "cwe": "CWE-22",
      "title": "Path traversal in LXD btrfs storage driver allows arbitrary file deletion and write on host as root",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85185"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-88804",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SUSE",
      "product": "Rancher",
      "cwe": "CWE-79",
      "title": "Unauthenticated update of public UI settings leading to stored cross-site scripting in Rancher",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88804"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-19759",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google Cloud",
      "product": "Application Integration",
      "cwe": "CWE-863",
      "title": "Incorrect Authorization in Application Integration allows Internal Stubby RPC Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19759"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-81867",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google Cloud",
      "product": "Application Integration",
      "cwe": "CWE-502",
      "title": "Deserialization of Untrusted Data in Application Integration allows Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81867"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-101263",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ziroom",
      "product": "ZHOME A0101",
      "cwe": "CWE-77",
      "title": "Ziroom ZHOME A0101 set_online_client command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101263"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-101264",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ziroom",
      "product": "ZHOME A0101",
      "cwe": "CWE-77",
      "title": "Ziroom ZHOME A0101 set_passwd command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101264"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-73640",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dayforce",
      "product": "Payroll",
      "cwe": "CWE-89",
      "title": "Time-based SQL Injection in Dayforce Payroll",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73640"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-86102",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "WatchGuard AP",
      "cwe": "CWE-78",
      "title": "WatchGuard AP Command Injection in Internal Management API Allows Command Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86102"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-100752",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ordasoft.com",
      "product": "Real Estate Manager (Free) extension for Joomla",
      "cwe": "CWE-89",
      "title": "Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estate Manager (Free) < 6.7.9",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100752"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-101039",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FAST",
      "product": "FAC1900R",
      "cwe": "CWE-119",
      "title": "FAST FAC1900R devdiscover Service copy_msg_element stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101039"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-101072",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netcore",
      "product": "NR289-GE",
      "cwe": "CWE-77",
      "title": "Netcore NR289-GE CGI ap_ip.cgi system os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101072"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-101075",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netcore",
      "product": "NR289-GE",
      "cwe": "CWE-77",
      "title": "Netcore NR289-GE Location Time location_time.cgi system os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101075"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-101076",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netcore",
      "product": "NR289-GE",
      "cwe": "CWE-77",
      "title": "Netcore NR289-GE CGI set_ntp_server_ip.cgi system os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101076"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-101077",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netcore",
      "product": "NR289-GE",
      "cwe": "CWE-287",
      "title": "Netcore NR289-GE boa_temp process_request missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101077"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-101108",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ordasoft.com",
      "product": "Vehicle Manager (Free) extension for Joomla",
      "cwe": "CWE-89",
      "title": "Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Vehicle Manager (Free) < 6.5.8",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101108"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-101110",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ordasoft.com",
      "product": "Book Library (Free) extension for Joomla",
      "cwe": "CWE-89",
      "title": "Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Book Library (Free) < 6.4.6",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101110"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-101891",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "WatchGuard AP",
      "cwe": "CWE-284",
      "title": "WatchGuard AP Improper Access Control in API Service Allows Unauthenticated Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101891"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-102361",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gz-yami",
      "product": "mall4j",
      "cwe": "CWE-306",
      "title": "mall4j through 4.0 Missing Authentication in Password Update Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102361"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-73642",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dayforce",
      "product": "Payroll",
      "cwe": "CWE-22",
      "title": "Path Traversal in Dayforce Payroll",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73642"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-49994",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dannymcc",
      "product": "bluehood",
      "cwe": "CWE-306",
      "title": "Bluehood: Missing authentication on Bluehood API routes when web auth is enabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49994"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-101894",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "XhmikosR",
      "product": "decompress",
      "cwe": "CWE-22",
      "title": "@xhmikosr/decompress: Path traversal via symlink chain",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101894"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-102268",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jpadilla",
      "product": "pyjwt",
      "cwe": "CWE-347",
      "title": "PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip the HS/asymmetric confusion guard",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102268"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-102334",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NginxProxyManager",
      "product": "nginx-proxy-manager",
      "cwe": "CWE-307",
      "title": "Nginx Proxy Manager through 2.16.0 Missing Brute-Force Protection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102334"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-101074",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netcore",
      "product": "NR289-GE",
      "cwe": "CWE-119",
      "title": "Netcore NR289-GE Authentication boa password-check stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101074"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-12264",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zohocorp",
      "product": "DDI Central",
      "cwe": "CWE-434",
      "title": "Authenticated File Write via HA Failover Config Upload leads to RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12264"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-12265",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zohocorp",
      "product": "DDI Central",
      "cwe": "CWE-284",
      "title": "Missing Authorization on HA Failover Config allows Complete Data Destruction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12265"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-12268",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zohocorp",
      "product": "DDI Central",
      "cwe": "CWE-20",
      "title": "Authenticated PowerShell Injection leads to RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12268"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-12269",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zohocorp",
      "product": "DDI Central",
      "cwe": "CWE-269",
      "title": "Authenticated File Write to RCE via keepalived in DDI Central",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12269"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-78424",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SUSE",
      "product": "NeuVector",
      "cwe": "CWE-78",
      "title": "OS Command Injection in Packet-Capture (Sniffer) Filter leading to Remote Code Execution on Kubernetes Nodes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78424"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-86595",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Iron Mountain Archiving Services Inc.",
      "product": "enVision",
      "cwe": "CWE-89",
      "title": "SQLi in Iron Mountain's enVision",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86595"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-86950",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-787",
      "title": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86950"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-87741",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Brainstorm Force",
      "product": "ConvertPlus",
      "cwe": "CWE-78",
      "title": "ConvertPlus <= 3.6.3 - Authenticated (Subscriber+) PHP Object Injection via 'style' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87741"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-88808",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SUSE",
      "product": "Rancher",
      "cwe": "CWE-250",
      "title": "Fleet agent copies downstream resources with cluster-admin privileges, allowing cross-namespace writes on downstream clusters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88808"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-90926",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Innotim Software, Telecommunications and Consultancy Trade Ltd. Co.",
      "product": "Logsign SIEM",
      "cwe": "CWE-94",
      "title": "Code Injection in Innotim Software's Logsign SIEM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90926"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-48100",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "polybase",
      "product": "payy",
      "cwe": "CWE-349",
      "title": "Payy: agg_agg trailing message slots are unconstrained and allow forged burn messages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48100"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-54675",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreePBX",
      "product": "security-reporting",
      "cwe": "CWE-22",
      "title": "FreePBX: Authenticated Remote Code Execution via File Upload and Convert in Soundlang Module",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54675"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-96538",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EnterpriseDB",
      "product": "WarehousePG",
      "cwe": "CWE-862",
      "title": "WarehousePG pg_file_write/pg_file_rename/pg_file_unlink/pg_logdir_ls privilege escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96538"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-100371",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "InvoicePlane",
      "product": "InvoicePlane",
      "cwe": "CWE-863",
      "title": "InvoicePlane: Incomplete Authorization Remediation in Users::form() Enables Primary Administrator Account Takeover via Email Reassignment and Password Recovery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100371"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2024-42002",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open Source Robotics Foundation",
      "product": "Robot Operating System 2 (ROS 2)",
      "cwe": "CWE-94",
      "title": "Unsafe use of eval() method in ros2 topic hz tool",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-42002"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-54674",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreePBX",
      "product": "security-reporting",
      "cwe": "CWE-78",
      "title": "Authenticated Command Injection in FreePBX UCP Interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54674"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-54708",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreePBX",
      "product": "security-reporting",
      "cwe": "CWE-22",
      "title": "Authenticated Remote Code Execution via Path Traversal in FreePBX Backup Module",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54708"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-54710",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreePBX",
      "product": "security-reporting",
      "cwe": "CWE-20",
      "title": "FreePBX: Authenticated Superfecta Arbitrary PHP Code Execution (RCE via Unsafe File Inclusion)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54710"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-75600",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreePBX",
      "product": "security-reporting",
      "cwe": "CWE-78",
      "title": "FreePBX: Authenticated API generatedocs Host Command Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75600"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-87969",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "WatchGuard AP",
      "cwe": "CWE-78",
      "title": "WatchGuard AP Authenticated Command Injection in Diagnostic CLI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87969"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-93348",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "unslothai",
      "product": "unsloth-zoo",
      "cwe": "CWE-94",
      "title": "Unsloth Zoo Code Injection via model_type in config.json",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93348"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-101038",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FAST",
      "product": "FAC1200R",
      "cwe": "CWE-119",
      "title": "FAST FAC1200R MmtAtePrase stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101038"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-101081",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "DI-8400",
      "cwe": "CWE-119",
      "title": "D-Link DI-8400 Web Administration Service menu_nat_more.asp menu_nat_more_asp stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101081"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-101187",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ziroom",
      "product": "ZHOME A0101",
      "cwe": "CWE-74",
      "title": "Ziroom ZHOME A0101 USB Device Management API zrUsb.lua pop_usb_device command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101187"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-101260",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ziroom",
      "product": "ZHOME A0101",
      "cwe": "CWE-74",
      "title": "Ziroom ZHOME A0101 firstLogin command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101260"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-101261",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ziroom",
      "product": "ZHOME A0101",
      "cwe": "CWE-74",
      "title": "Ziroom ZHOME A0101 firstSetup_wifi command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101261"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-101262",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ziroom",
      "product": "ZHOME A0101",
      "cwe": "CWE-74",
      "title": "Ziroom ZHOME A0101 set_online_client command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101262"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-55157",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ooples",
      "product": "token-optimizer-mcp",
      "cwe": "CWE-78",
      "title": "Token Optimizer MCP: OS command injection in smart_user via username in get-user-info",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55157"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-81375",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google Cloud",
      "product": "Application Integration",
      "cwe": "CWE-610",
      "title": "Confused Deputy in Application Integration allows Internal File Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81375"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-101909",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "axios",
      "product": "axios",
      "cwe": "CWE-1321",
      "title": "Axios: Prototype Pollution Gadget in axios toFormData Options",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101909"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-102296",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZoneMinder",
      "product": "zoneminder",
      "cwe": "CWE-120",
      "title": "ZoneMinder before 1.38.4 Buffer Overflow via HTTP Camera Response",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102296"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-54160",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "networkupstools",
      "product": "nut",
      "cwe": "CWE-829",
      "title": "Network UPS Tools: A PWN Request in make-dist workflow can execute PR-controlled code with write-scoped GITHUB_TOKEN",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54160"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-91043",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "elixir-mint",
      "product": "mint",
      "cwe": "CWE-770",
      "title": "HPACK-indexed cookie fields in Mint HTTP/2 responses bypass max_header_list_size and exhaust client memory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91043"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-101292",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat AMQ Broker 7",
      "cwe": "CWE-470",
      "title": "Artemis-core-client: unsafe reflection in apache activemq artemis federation message deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101292"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-101901",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "axios",
      "product": "axios",
      "cwe": "CWE-400",
      "title": "Axios: Denial of Service via Unhandled 'error' Event in HTTP/2 ClientHttp2Session Initialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101901"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-101903",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "axios",
      "product": "axios",
      "cwe": "CWE-1333",
      "title": "Axios: ReDoS in fromDataURI data: URL parser freezes the Node event loop (DoS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101903"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-101906",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "axios",
      "product": "axios",
      "cwe": "CWE-400",
      "title": "Axios: ReDoS (O(N²)) in shouldBypassProxy host normalization, reachable via untrusted redirect Location",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101906"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-82323",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Enocta Educational Technologies Inc.",
      "product": "Enocta Platform",
      "cwe": "CWE-639",
      "title": "Improper Authorization in Enocta Educational's Enocta Platform",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82323"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-88805",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SUSE",
      "product": "Rancher",
      "cwe": "CWE-613",
      "title": "Session Not Revoked Server-Side on Logout in Rancher",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88805"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-4556",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Extegrity",
      "product": "Exam4",
      "cwe": "CWE-78",
      "title": "macOS Exam4 Local Privilege Escalation via Command Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4556"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-16513",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-787",
      "title": "Missing write validation of user-supplied handle pointer in the RTIO syscall verifier allows arbitrary kernel write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16513"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-18413",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-787",
      "title": "Out-of-bounds write in the NXP MCUX LPADC ADC driver due to missing adc_sequence buffer size validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18413"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-18414",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-787",
      "title": "Out-of-bounds write in the ADI MAX32 ADC driver due to incorrect adc_sequence buffer size validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18414"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-102004",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wind River Systems Inc",
      "product": "VxWorks 7",
      "cwe": "CWE-787",
      "title": "VxWorks 7",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102004"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-45562",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreePBX",
      "product": "security-reporting",
      "cwe": "CWE-78",
      "title": "FreePBX: Authenticated Remote Code Execution in FreePBX Music on Hold (MoH) Module",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45562"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-82928",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "F&F Filipowski",
      "product": "mH-DEVELOPER",
      "cwe": "CWE-1242",
      "title": "Undocumented access path in mH-DEVELOPER",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82928"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-97335",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canonical",
      "product": "LXD",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in LXD storage volume API allows reading volumes from other projects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97335"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-55160",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stringer-rss",
      "product": "stringer",
      "cwe": "CWE-918",
      "title": "Authenticated Server-Side Request Forgery (SSRF) via feed URL in Stringer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55160"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-93355",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BerriAI",
      "product": "litellm",
      "cwe": "CWE-1390",
      "title": "LiteLLM Weak JWT Authentication via Email-Based User Lookup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93355"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-101905",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "axios",
      "product": "axios",
      "cwe": "CWE-441",
      "title": "Axios: Node HTTP adapter prototype-pollution gadget allows request socket hijack via inherited createConnection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101905"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-102276",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "juliangruber",
      "product": "brace-expansion",
      "cwe": "CWE-400",
      "title": "brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102276"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-102278",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "juliangruber",
      "product": "brace-expansion",
      "cwe": "CWE-400",
      "title": "brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102278"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-102281",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nestjs",
      "product": "nest",
      "cwe": "CWE-248",
      "title": "Nest: Remote process termination via a deeply nested microservice message pattern",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102281"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-101916",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grpc",
      "product": "grpc-node",
      "cwe": "CWE-295",
      "title": "@grpc/grpc-js: In certain configurations, getAuthContext can return unauthorized certificates as though they were authorized",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101916"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-102266",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jpadilla",
      "product": "pyjwt",
      "cwe": "CWE-347",
      "title": "PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102266"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-102267",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jpadilla",
      "product": "pyjwt",
      "cwe": "CWE-200",
      "title": "PyJWT: PyJWKClient follows redirects when fetching JWKS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102267"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-102271",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jpadilla",
      "product": "pyjwt",
      "cwe": "CWE-347",
      "title": "PyJWT: Public keys in DER form are accepted as HMAC secrets, bypassing the CVE-2022-29217 guard",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102271"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-102272",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jpadilla",
      "product": "pyjwt",
      "cwe": "CWE-347",
      "title": "PyJWT BOM Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102272"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-102273",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jpadilla",
      "product": "pyjwt",
      "cwe": "CWE-347",
      "title": "PyJWT accepts public JWK containers as HMAC secrets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102273"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-12267",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zohocorp",
      "product": "DDI Central",
      "cwe": "CWE-20",
      "title": "Authenticated PowerShell Injection in DNS Query Resolution Policy leads to RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12267"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-86330",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Openshift Data Foundation 4",
      "cwe": "CWE-78",
      "title": "Noobaa-core: noobaa-core: os command injection in cluster_internal_api.set_hostname_internal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86330"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2024-58386",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZoneMinder",
      "product": "zoneminder",
      "cwe": "CWE-22",
      "title": "ZoneMinder 1.37.x Path Traversal via files view",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-58386"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-15952",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ABB",
      "product": "Protection and control IED manager (PCM600)",
      "cwe": "CWE-732",
      "title": "Improper Permission Assignment in Scheduler Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15952"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-52748",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kaon",
      "product": "AR2140",
      "cwe": "CWE-306",
      "title": "Missing authentication for backup functionality in Kaon AR2140X",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52748"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-55096",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "leshchenko1979",
      "product": "fast-mcp-telegram",
      "cwe": "CWE-184",
      "title": "SSRF via DNS-resolution gap in _validate_url_security (file download by URL)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55096"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-87114",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Pen Drive Powered by Red Hat Lightspeed",
      "cwe": "CWE-829",
      "title": "Kube-compare: container:// reference extraction runs the image entrypoint and silently escalates to sudo",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87114"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-90925",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Innotim Software, Telecommunications and Consultancy Trade Ltd. Co.",
      "product": "Logsign SIEM",
      "cwe": "CWE-22",
      "title": "Path Traversal in Innotim Software's Logsign SIEM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90925"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-93538",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SUSE",
      "product": "Rancher",
      "cwe": "CWE-290",
      "title": "Cross-tenant BundleDeployment and Secret disclosure via spoofed cluster labels during agent-initiated registration in Fleet",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93538"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-97023",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-61",
      "title": "Flatpak: flatpak: arbitrary file deletion in root context via path traversal in deploy directory export/bin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97023"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-101091",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-89",
      "title": "SiYuan before v3.8.4 SQL Injection via Block Query Embed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101091"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-102335",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NginxProxyManager",
      "product": "nginx-proxy-manager",
      "cwe": "CWE-863",
      "title": "Nginx Proxy Manager through 2.16.0 Improper Authorization via advanced_config",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102335"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-102365",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gz-yami",
      "product": "mall4j",
      "cwe": "CWE-862",
      "title": "mall4j through 4.0 Missing Authorization in Admin User Address Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102365"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-80357",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Boot Optimized Server Storage (BOSS)",
      "cwe": "CWE-1191",
      "title": "Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU on 17G BOSS-N1 controllers. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Unauthorized access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80357"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-100392",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "InvoicePlane",
      "product": "InvoicePlane",
      "cwe": "CWE-863",
      "title": "InvoicePlane: Primary Administrator Privilege Downgrade via `Users::form()` (Missing Object-Level Authorization)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100392"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-101898",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "axios",
      "product": "axios",
      "cwe": "CWE-918",
      "title": "Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101898"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-101907",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "axios",
      "product": "axios",
      "cwe": "CWE-441",
      "title": "Axios: maxRedirects: 0 is not enforced by the fetch adapter, allowing redirect-based SSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101907"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-102010",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-825",
      "title": "Gcc-toolset-15-gcc: gcc: gcc-toolset-16: gcc: denial of service via use-after-free in binary heap erase_if",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102010"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-82935",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "F&F Filipowski",
      "product": "mH-DEVELOPER",
      "cwe": "CWE-1104",
      "title": "Use of End-of-Life components in mH-DEVELOPER",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82935"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-91154",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MarcosCamara01",
      "product": "Ecommerce Template",
      "cwe": "CWE-306",
      "title": "Missing authentication in Ecommerce Template product cache revalidation allows unauthenticated denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91154"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-101083",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "PMWeb",
      "cwe": "CWE-200",
      "title": "PMWeb encryptionhelper.dll information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101083"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-101092",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-200",
      "title": "SiYuan before v3.8.4 Information Disclosure via getCurrentAttrViewImages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101092"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-101277",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Trusted Domain Project",
      "product": "OpenDKIM",
      "cwe": "CWE-348",
      "title": "Trusted Domain Project OpenDKIM Tag Tokenizer dkim.c dkim_process_set less trusted source",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101277"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-101900",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "axios",
      "product": "axios",
      "cwe": "CWE-74",
      "title": "Axios: Fetch Adapter Header Injection via Inherited FormData getHeaders",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101900"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-101902",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "axios",
      "product": "axios",
      "cwe": "CWE-1321",
      "title": "Axios: Prototype-Pollution Gadget in the Default Instance Allows Inherited Object.prototype.method to Override HTTP Method",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101902"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-101904",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "axios",
      "product": "axios",
      "cwe": "CWE-74",
      "title": "Axios: Header Injection via Inherited headers After Minimal Interceptor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101904"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-101908",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "axios",
      "product": "axios",
      "cwe": "CWE-1321",
      "title": "Axios: Prototype pollution gadget in fetch adapter can alter outbound requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101908"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-101910",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "beaugunderson",
      "product": "ip-address",
      "cwe": "CWE-918",
      "title": "ip-address: no classifier recognizes the NAT64 local-use range 64:ff9b:1::/48, allowing SSRF and trust-boundary bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101910"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-102362",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gz-yami",
      "product": "mall4j",
      "cwe": "CWE-306",
      "title": "mall4j through 4.0 Missing Authentication in Product Review Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102362"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-18747",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-125",
      "title": "Integer underflow of net_buf length in the MCUmgr serial (SMP over console) transport leads to out-of-bounds read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18747"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-80359",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Boot Optimized Server Storage (BOSS)",
      "cwe": "CWE-1191",
      "title": "Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU on 17G BOSS-N1 controllers. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Unauthorized access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80359"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-18417",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-843",
      "title": "Wild pointer dereference in Zephyr BSD sockets when a TCP listening socket reports an asynchronous error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18417"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-19444",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kubernetes",
      "product": "Kubernetes",
      "cwe": "CWE-22",
      "title": "Kubernetes kubectl cp path traversal on Windows allows arbitrary file writes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19444"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-93537",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SUSE",
      "product": "Rancher",
      "cwe": "CWE-23",
      "title": "Path traversal in Fleet Helm valuesFiles allows disclosure of files outside the bundle directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93537"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-93540",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SUSE",
      "product": "Rancher",
      "cwe": "CWE-266",
      "title": "Fleet applies namespace labels and annotations without the bundle's service account privileges",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93540"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-96740",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "StreamsHub Console for Apache Kafka®",
      "cwe": "CWE-470",
      "title": "Streamshub/console: console-operator: streams for apache kafka console: unfiltered kafka client properties → sa-token exfiltration via config.providers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96740"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-101914",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grpc",
      "product": "grpc-node",
      "cwe": "CWE-187",
      "title": "@grpc/grpc-js: The exact path match matcher incorrectly only applies a prefix match for case-insensitive matches",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101914"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-102275",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jpadilla",
      "product": "pyjwt",
      "cwe": "CWE-345",
      "title": "PyJWT accepts inconsistent OKP x/d JWKs, causing public/private key identity confusion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102275"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-82930",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "F&F Filipowski",
      "product": "mH-DEVELOPER",
      "cwe": "CWE-306",
      "title": "Missing Authentication in mH-DEVELOPER",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82930"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-18415",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-787",
      "title": "Out-of-bounds write in the IEEE 802.15.4 L2 transmit path for oversized non-6LoWPAN frames",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18415"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-82929",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "F&F Filipowski",
      "product": "mH-DEVELOPER",
      "cwe": "CWE-321",
      "title": "Use of Shared Cryptographic Key in mH-DEVELOPER",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82929"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-86335",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canonical",
      "product": "LXD",
      "cwe": "CWE-862",
      "title": "LXD Cross-Project Private Image Theft via Unsanitized GetImageFromAnyProject Local Reuse",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86335"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-92103",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "elixir-mint",
      "product": "mint",
      "cwe": "CWE-770",
      "title": "Mint HTTP/2 client buffers oversized frames up to 16 MiB before enforcing max_frame_size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92103"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-94194",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "elixir-mint",
      "product": "mint",
      "cwe": "CWE-444",
      "title": "Mint HTTP/1 client applies chunked framing when chunked is not the final transfer coding, enabling response smuggling through intermediaries",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94194"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-101911",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "beaugunderson",
      "product": "ip-address",
      "cwe": "CWE-400",
      "title": "ip-address: Address6 builds a parse diagnostic proportional to the input with no length bound, allowing a single long string to stall or crash the process",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101911"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-101912",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "beaugunderson",
      "product": "ip-address",
      "cwe": "CWE-697",
      "title": "ip-address: isInSubnet() and isHostInSubnet() compare addresses of different families as if they shared an address space, allowing an allowlist check to admit an address outside its range",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101912"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-101913",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "beaugunderson",
      "product": "ip-address",
      "cwe": "CWE-697",
      "title": "ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SSRF and trust-boundary bypass to on-link hosts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101913"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-102363",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gz-yami",
      "product": "mall4j",
      "cwe": "CWE-306",
      "title": "mall4j through 4.0 Unauthenticated Shipment Tracking Disclosure via Order Number",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102363"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-87752",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rolantis Information Technologies Tourism Industry and Trade Co. Ltd.",
      "product": "Agentis",
      "cwe": "CWE-79",
      "title": "HTML Injection in Rolantis Information Technologies' Agentis",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87752"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-82933",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "F&F Filipowski",
      "product": "mH-DEVELOPER",
      "cwe": "CWE-1428",
      "title": "Cleartext Transmission of Sensitive Information in mH-DEVELOPER",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82933"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-18746",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-476",
      "title": "NULL pointer dereference in Zephyr LwM2M client when the CoAP Block1 context pool is exhausted",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18746"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-82936",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "F&F Filipowski",
      "product": "mH-DEVELOPER",
      "cwe": "CWE-770",
      "title": "Denial of Service in mH-DEVELOPER",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82936"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-102274",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jpadilla",
      "product": "pyjwt",
      "cwe": "CWE-755",
      "title": "PyJWT: Malformed RSA JWK aborts parsing of an entire JWK Set",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102274"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-87798",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canonical",
      "product": "LXD",
      "cwe": "CWE-59",
      "title": "LXD client recursive file pull allows directory escape via malicious VM agent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87798"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-101040",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ricoh",
      "product": "SP 330DN",
      "cwe": "CWE-404",
      "title": "Ricoh SP 330DN/SP 221/SP C252SF/Aficio SP 3500SF HTTP Multipart Form-Data denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101040"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-15953",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ABB",
      "product": "Protection and control IED manager (PCM600)",
      "cwe": "CWE-22",
      "title": "Path Traversal During Project Archive Import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15953"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-70413",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Live Optics Collector",
      "cwe": "CWE-259",
      "title": "Dell Live Optics Collector, versions prior to 27.2.13.310, contain(s) a Use of Hard-coded Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70413"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-97686",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wind River",
      "product": "VxWorks 7",
      "cwe": "CWE-772",
      "title": "VxWorks 7 Memory Resource leak",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97686"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-101052",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "refly-ai",
      "product": "refly",
      "cwe": "CWE-259",
      "title": "refly-ai refly JWT Token app.config.ts hard-coded credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101052"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-101053",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Thinkware",
      "product": "U3000",
      "cwe": "CWE-266",
      "title": "Thinkware U3000 TCP Service wpa_supplicant.conf PUT_FILE access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101053"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-101054",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Thinkware",
      "product": "U3000",
      "cwe": "CWE-266",
      "title": "Thinkware U3000 TCP Service wpa_supplicant.conf get_file access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101054"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-101055",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Thinkware",
      "product": "U3000",
      "cwe": "CWE-200",
      "title": "Thinkware U3000 TCP Service GET_STATUS information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101055"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-101066",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "dbgate",
      "cwe": "CWE-22",
      "title": "dbgate Archive Link Creation archive.js createLink path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101066"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-101067",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "dbgate",
      "cwe": "CWE-22",
      "title": "dbgate save-uploaded-file Endpoint files.js saveUploadedFile path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101067"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-101068",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "dbgate",
      "cwe": "CWE-22",
      "title": "dbgate Create Connection Endpoint zipJsonLinesData.js zipJsonLinesData path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101068"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-101069",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "dbgate",
      "cwe": "CWE-22",
      "title": "dbgate Export databaseConnections.js exportModelSql path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101069"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-101070",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "dbgate",
      "cwe": "CWE-22",
      "title": "dbgate Files Endpoint runners.js files path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101070"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-101073",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netcore",
      "product": "NR289-GE",
      "cwe": "CWE-287",
      "title": "Netcore NR289-GE CGI Dispatcher boa improper authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101073"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-101082",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "PMWeb",
      "cwe": "CWE-22",
      "title": "PMWeb downloader.aspx path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101082"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-101188",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netcore",
      "product": "POWER13",
      "cwe": "CWE-640",
      "title": "Netcore POWER13 ubus routerd.passwd_set password recovery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101188"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-102005",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wind River Inc",
      "product": "VxWorks 7",
      "cwe": "CWE-401",
      "title": "VxWorks Memory Allocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102005"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-102006",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wind River Systems Inc",
      "product": "VxWorks 7",
      "cwe": "CWE-401",
      "title": "VxWorks 7 Memory allocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102006"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-93539",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SUSE",
      "product": "Rancher",
      "cwe": "CWE-306",
      "title": "Unauthenticated GitRepo Spec Mutation via Fleet Git Webhook Receiver",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93539"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-18825",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "github.com/antono",
      "product": "connect-cors",
      "cwe": "CWE-346",
      "title": "Origin validation error in the connect-xcors npm package",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18825"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-52749",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kaon",
      "product": "AR2140",
      "cwe": "CWE-287",
      "title": "Improper Authentication in Kaon AR2140X",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52749"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-55156",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ooples",
      "product": "token-optimizer-mcp",
      "cwe": "CWE-22",
      "title": "Token Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log API Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55156"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-82932",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "F&F Filipowski",
      "product": "mH-DEVELOPER",
      "cwe": "CWE-923",
      "title": "Missing Firewall Configuration in mH-DEVELOPER",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82932"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-100753",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ordasoft.com",
      "product": "Real Estate Manager (Free) extension for Joomla",
      "cwe": "CWE-79",
      "title": "Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Real Estate Manager (Free) < 6.7.9",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100753"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-101093",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cotonti",
      "product": "Cotonti",
      "cwe": "CWE-352",
      "title": "Cotonti through 1.0.0 Cross-Site Request Forgery via User Group Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101093"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-101098",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ag-ui-protocol",
      "product": "ag-ui",
      "cwe": "CWE-400",
      "title": "ag-ui-protocol ag-ui HTTP JdkAgentHttpHandler.java readAllBytes resource consumption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101098"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-101099",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ag-ui-protocol",
      "product": "ag-ui",
      "cwe": "CWE-755",
      "title": "ag-ui-protocol ag-ui Kotlin Community SDK SseParser.kt exceptional condition",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101099"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-101100",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ag-ui-protocol",
      "product": "ag-ui",
      "cwe": "CWE-459",
      "title": "ag-ui-protocol ag-ui Middleware filter-tool-calls.ts FilterToolCallsMiddleware cleanup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101100"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-101101",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ag-ui-protocol",
      "product": "ag-ui",
      "cwe": "CWE-248",
      "title": "ag-ui-protocol ag-ui Middleware convert.ts JSON.parse uncaught exception",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101101"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-101102",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "deepseek-ai",
      "product": "deepseek-harness",
      "cwe": "CWE-264",
      "title": "deepseek-ai deepseek-harness Code Mode Sandbox run_code sandbox",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101102"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-101109",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ordasoft.com",
      "product": "Vehicle Manager (Free) extension for Joomla",
      "cwe": "CWE-79",
      "title": "Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Vehicle Manager (Free) < 6.5.8",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101109"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-101111",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ordasoft.com",
      "product": "Book Library (Free) extension for Joomla",
      "cwe": "CWE-79",
      "title": "Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Book Library (Free) < 6.4.6",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101111"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-101917",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jpadilla",
      "product": "pyjwt",
      "cwe": "CWE-770",
      "title": "PyJWT: PyJWKClient still amplifies unauthenticated JWKS fetches on unknown kid values (incomplete fix of CVE-2026-48524)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101917"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-101918",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jpadilla",
      "product": "pyjwt",
      "cwe": "CWE-248",
      "title": "PyJWT: Unauthenticated RecursionError DoS in pre-verification payload parse (PyJWKClient.get_signing_key_from_jwt / verify_signature=False)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101918"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-102265",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jpadilla",
      "product": "pyjwt",
      "cwe": "CWE-674",
      "title": "PyJWT: Uncaught RecursionError in jwt.decode() on deeply nested token header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102265"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-102277",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "juliangruber",
      "product": "brace-expansion",
      "cwe": "CWE-400",
      "title": "brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102277"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-102297",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZoneMinder",
      "product": "zoneminder",
      "cwe": "CWE-863",
      "title": "ZoneMinder before 1.38.4 Incorrect Authorization in frames API index",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102297"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-102333",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cle-b",
      "product": "httpdbg",
      "cwe": "CWE-79",
      "title": "httpdbg before 2.2.1 Stored Cross-Site Scripting via javascript URL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102333"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-102364",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gz-yami",
      "product": "mall4j",
      "cwe": "CWE-287",
      "title": "mall4j through 4.0 Improper Authentication Accepts Storefront Tokens on Admin API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102364"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-102367",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gz-yami",
      "product": "mall4j",
      "cwe": "CWE-613",
      "title": "mall4j through 4.0 Insufficient Session Expiration via Token Refresh",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102367"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-73641",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dayforce",
      "product": "Payroll",
      "cwe": "CWE-79",
      "title": "Multiple Reflected XSS in Dayforce Payroll",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73641"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-80358",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Boot Optimized Server Storage (BOSS)",
      "cwe": "CWE-1191",
      "title": "Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU on 17G BOSS-N1 controllers. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Unauthorized access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80358"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-102269",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jpadilla",
      "product": "pyjwt",
      "cwe": "CWE-180",
      "title": "PyJWT: Non-canonical signature segments enable raw-token revocation bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102269"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-100370",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rhukster",
      "product": "dom-sanitizer",
      "cwe": "CWE-20",
      "title": "DOMSanitizer - Incomplete data: URL Sanitization in DOMSanitizer::isDangerousUrl() Allows Base64-Encoded Payloads to Bypass href and xlink:href Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100370"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-59563",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zscaler",
      "product": "zscaler-mcp-server",
      "cwe": "CWE-305",
      "title": "HMAC Confirmation Token Unbinding in zscaler-mcp-server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59563"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-102332",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "amir20",
      "product": "dozzle",
      "cwe": "CWE-22",
      "title": "Dozzle before 11.1.2 Path Traversal via Log ZIP Download",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102332"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-102270",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jpadilla",
      "product": "pyjwt",
      "cwe": "CWE-1333",
      "title": "PyJWT: ReDoS vulnerability when calling the `is_pem_format` function.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102270"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-13018",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Codecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially perform out of bounds memory access via a crafted video file. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13018"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-86334",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canonical",
      "product": "LXD",
      "cwe": "CWE-22",
      "title": "CLI Path Traversal via Content-Disposition in LXD Image Export/Copy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86334"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-82326",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Enocta Educational Technologies Inc.",
      "product": "Enocta Platform",
      "cwe": "CWE-79",
      "title": "HTML Injection in Enocta Educational's Enocta Platform",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82326"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-97026",
      "cvss_base": 3.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-378",
      "title": "Flatpak: flatpak: world-writable temporary child repositories in system-helper cache path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97026"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-18416",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-125",
      "title": "Out-of-bounds read in CoAP well-known-core Uri-Query href matching (match_path_uri)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18416"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-97399",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The GNU C Library",
      "product": "glibc",
      "cwe": "CWE-126",
      "title": "One-byte overread in strncasecmp on Power8",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97399"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-101333",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-770",
      "title": "Keycloak-services: keycloak-services: unbounded metric series creation via idp tag on broker login endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101333"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-101915",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grpc",
      "product": "grpc-node",
      "cwe": "CWE-550",
      "title": "@grpc/grpc-js: The server transmits some error messages thrown by method handlers to the client in status messages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101915"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-97027",
      "cvss_base": 3.6,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-20",
      "title": "Flatpak: flatpak: denial of service via unsanitized keys in exported desktop entry / d-bus service files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97027"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-97025",
      "cvss_base": 3.2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-378",
      "title": "Flatpak: flatpak: world-readable oci authentication token in system-helper cache path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97025"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-102279",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "laravel",
      "product": "framework",
      "cwe": "CWE-80",
      "title": "Laravel: XSS in Debug Page Information",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102279"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-101265",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Intelbras",
      "product": "TIP 125i",
      "cwe": "CWE-540",
      "title": "Intelbras TIP 125i Básico sensitive information in source",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101265"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-101071",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acrel Electric",
      "product": "Unet Web Service",
      "cwe": "CWE-284",
      "title": "Acrel Electric Unet Web Service Upload Endpoint upload unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101071"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-101105",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Matrimonial System",
      "cwe": "CWE-74",
      "title": "code-projects Matrimonial System Profile Creation Endpoint create_profile processprofile_form sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101105"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-101142",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eleveo",
      "product": "Quality Management",
      "cwe": "CWE-22",
      "title": "Eleveo Quality Management Questionnaire Audio Upload Scorecard.jsp path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101142"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-101143",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eleveo",
      "product": "Quality Management",
      "cwe": "CWE-200",
      "title": "Eleveo Quality Management QMBODownload information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101143"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-101144",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eleveo",
      "product": "Call Recording Software",
      "cwe": "CWE-266",
      "title": "Eleveo Call Recording Software Query Builder searchAction.do access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101144"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-101145",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eleveo",
      "product": "Call Recording Software",
      "cwe": "CWE-74",
      "title": "Eleveo Call Recording Software User Management userAddAction.do ldap injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101145"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-101146",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eleveo",
      "product": "Quality Management",
      "cwe": "CWE-200",
      "title": "Eleveo Quality Management GWT RPC QMUtilsService UtilsService.createAndSaveAudit information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101146"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-101202",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FastStone",
      "product": "Image Viewer",
      "cwe": "CWE-119",
      "title": "FastStone Image Viewer TGA Image out-of-bounds write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101202"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-101203",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FastStone",
      "product": "Image Viewer",
      "cwe": "CWE-119",
      "title": "FastStone Image Viewer 1bpp RLE Decoder out-of-bounds write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101203"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-101204",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FastStone",
      "product": "Image Viewer",
      "cwe": "CWE-119",
      "title": "FastStone Image Viewer TGA Image FSViewer.exe out-of-bounds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101204"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-101205",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FastStone",
      "product": "Image Viewer",
      "cwe": "CWE-119",
      "title": "FastStone Image Viewer PCX Decoder out-of-bounds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101205"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-101861",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "langflow-ai",
      "product": "langflow",
      "cwe": "CWE-94",
      "title": "Langflow Code Execution via eval() in Component Input Schema",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101861"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-102366",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gz-yami",
      "product": "mall4j",
      "cwe": "CWE-434",
      "title": "mall4j through 4.0 Unrestricted File Upload in Admin File Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102366"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-101139",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webkul",
      "product": "Bagisto",
      "cwe": "CWE-862",
      "title": "Webkul Bagisto Invoice Mass Status Update state authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101139"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-101141",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eleveo",
      "product": "Call Recording Software",
      "cwe": "CWE-79",
      "title": "Eleveo Call Recording Software Play Audio audio.jsp cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101141"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-101078",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "deepseek-ai",
      "product": "deepseek-harness",
      "cwe": "CWE-653",
      "title": "deepseek-ai deepseek-harness Landlock Backend profiles.ts isolation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101078"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-101131",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "deepseek-ai",
      "product": "deepseek-harness",
      "cwe": "CWE-20",
      "title": "deepseek-ai deepseek-harness dsh index.ts reliance on untrusted inputs in a security decision",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101131"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-101132",
      "cvss_base": 1.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DeepSeek",
      "product": "deepseek-harness",
      "cwe": "CWE-22",
      "title": "DeepSeek deepseek-harness Bundle Patch profile.ts loadProfile path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101132"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-101079",
      "cvss_base": 0.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "agentverus",
      "product": "agentverus-scanner",
      "cwe": "CWE-20",
      "title": "agentverus agentverus-scanner context.js isSecurityDefenseSkill reliance on untrusted inputs in a security decision",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101079"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-101080",
      "cvss_base": 0.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tencent",
      "product": "AI-Infra-Guard",
      "cwe": "CWE-22",
      "title": "Tencent AI-Infra-Guard File Access dir_actions.py startsWith path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101080"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-84894",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Meta Platforms, Inc",
      "product": "moxygen",
      "cwe": null,
      "title": "In moxygen before commit 004123dd24c3, MoQSession::dataStreamReadLoop keeps using a stream read handle after reading a FIN, which invalidates the handle under proxygen's WebTransport API. A remote peer can trigger the stale use by opening a data stream that names an unknown track alias and carries the FIN in the same write.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84894"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-84895",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Facebook",
      "product": "proxygen",
      "cwe": null,
      "title": "In proxygen from v2026.04.06.00 until v2026.09.28.00, QuicWtSession::closeSession accesses its member fields after calling the base QuicWtSessionBase::closeSession method. The base method notifies the session handler, which may release the last reference to the session and destroy it.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84895"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-85644",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "XS-Parse-Keyword",
      "cwe": "CWE-125",
      "title": "XS::Parse::Infix versions from 0.40 through 0.49 for Perl treat a number as an array reference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85644"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-88815",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "DBI",
      "cwe": "CWE-843",
      "title": "DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in sql_type_cast_svpv",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88815"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-88816",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "DBI",
      "cwe": "CWE-843",
      "title": "DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in FetchHashKeyName",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88816"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-91006",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Karaf",
      "cwe": "CWE-78",
      "title": "Apache Karaf: OS Command Injection in Child-Instance Launch (instance:* / InstancesMBean)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91006"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-91095",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Facebook",
      "product": "proxygen",
      "cwe": null,
      "title": "In proxygen from v2024.10.28.00 until v2026.09.28.00, the HTTPTransaction::onWebTransportUniStream and HTTPTransaction::onWebTransportBidiStream APIs could return stream handles that the stream handler had already freed. HQSession then installed those handles as transport read callbacks, which could lead to use of freed memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91095"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-91096",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Facebook",
      "product": "proxygen",
      "cwe": null,
      "title": "In proxygen from v2024.10.28.00 until v2026.09.28.00, WebTransportImpl::terminateSessionStreams (WebTransportImpl::destroy in releases before v2025.08.18.00) failed to unregister read callbacks for streams that were no longer open before destroying them. The transport could then invoke a read callback that had been freed.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91096"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-96760",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Authlib",
      "product": "Authlib",
      "cwe": null,
      "title": "Authlib library contains a signature‑verification bypass vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96760"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-100311",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-100311 (mathurvishal CloudClassroom-PHP-Project). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-100313",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-100313 (mathurvishal CloudClassroom-PHP-Project). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-100314",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-100314 (mathurvishal CloudClassroom-PHP-Project). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-100739",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-100739 (mathurvishal CloudClassroom-PHP-Project). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-100740",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-100740 (D-Link DIR-895L). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-100745",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-100745 (Edimax BR-6428nC). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-100746",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-100746 (coollabsio Coolify). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-100874",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-100874 (mathurvishal CloudClassroom-PHP-Project). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-100875",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-100875 (mathurvishal CloudClassroom-PHP-Project). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-100877",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-100877 (mathurvishal CloudClassroom-PHP-Project). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-100878",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-100878 (zhistaredu StarTraining). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-100880",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-100880 (zhistaredu StarTraining). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-100881",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-100881 (zhistaredu StarTraining). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-100883",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-100883 (Krayin laravel-crm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-100884",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-100884 (Krayin laravel-crm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-100886",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-100886 (Seetong T8108). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45747",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45747 (OISF suricata). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-57225",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-57225 (OISF suricata). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-57226",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-57226 (OISF suricata). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73558",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73558 (vllm-project vllm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73559",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73559 (vllm-project vllm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73624",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73624 (gitpython-developers GitPython). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-77246",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-77246 (sooperset mcp-atlassian). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-77247",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-77247 (sooperset mcp-atlassian). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-77253",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-77253 (sooperset mcp-atlassian). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-77254",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-77254 (sooperset mcp-atlassian). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-77266",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-77266 (sooperset mcp-atlassian). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-77270",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-77270 (sooperset mcp-atlassian). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-77271",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-77271 (sooperset mcp-atlassian). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-77272",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-77272 (sooperset mcp-atlassian). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-77274",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-77274 (sooperset mcp-atlassian). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-79759",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-79759 (Termix-SSH Termix). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-81655",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-81655 (Unknown Ad Inserter). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-81882",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-81882 (radareorg radare2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-81883",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-81883 (radareorg radare2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-81884",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-81884 (radareorg radare2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-81885",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-81885 (radareorg radare2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-81886",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-81886 (radareorg radare2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82841",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82841 (Unknown UpdraftPlus: WP Backup & Migration Plugin). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-84069",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-84069 (Unknown WebFacing™). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-85002",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-85002 (Unknown EmbedPress). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86609",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86609 (Unknown Download Manager). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86839",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86839 (Unknown Online Scheduling and Appointment Booking System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86841",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86841 (Unknown Online Scheduling and Appointment Booking System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-89000",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-89000 (Unknown WPeMatico RSS Feed Fetcher). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-89001",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-89001 (Unknown WPeMatico RSS Feed Fetcher). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-89003",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-89003 (Unknown WPeMatico RSS Feed Fetcher). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-89006",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-89006 (Unknown WPeMatico RSS Feed Fetcher). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-92436",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-92436 (Unknown Mailchimp for WooCommerce). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-92995",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-92995 (Unknown Verge3D Publishing and E-Commerce). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-93353",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-93353 (9001 copyparty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-93592",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-93592 (vllm-project vllm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-95847",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-95847 (moquette-io moquette). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-95848",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-95848 (moquette-io moquette). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-96550",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-96550 (sfturing hosp_order). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-96602",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-96602 (Abdurrab5 online-makeup-store). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-96678",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-96678 (weiqingwen spring-boot-forum). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-96763",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-96763 (kvcache-ai mooncake). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-96777",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-96777 (Forma LMS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-96882",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-96882 (TaleLin lin-cms-spring-boot). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-96895",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-96895 (Unknown WP YouTube Lyte). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-96896",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-96896 (Unknown Malcure Malware Shield — Removal, Repair, Monitor). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-96897",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-96897 (Unknown Optima Express IDX). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-96899",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-96899 (Unknown Optima Express IDX). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-97227",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-97227 (Unknown NextScripts: Social Networks Auto-Poster). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-97231",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-97231 (volotat Anagnorisis). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-97319",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-97319 (Unknown PowerPress Podcasting plugin by Blubrry). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-97359",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-97359 (rejetto hfs2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-97647",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-97647 (ningzichun student-management-system). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-5430",
      "detail": "DUE DATE PASSED — CVE-2026-5430 (WSO2 Universal Gateway). CISA remediation deadline was September 27, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-71362",
      "detail": "DUE DATE PASSED — CVE-2026-71362 (Adobe Commerce). CISA remediation deadline was September 27, 2026; still in catalog."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-100887",
      "detail": "RESCORED — CVE-2026-100887 (amirsanni Mini-Inventory-and-Sales-Management-System). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-100888",
      "detail": "RESCORED — CVE-2026-100888 (Trusted Domain Project OpenDKIM). CVSS 6.9 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-100889",
      "detail": "RESCORED — CVE-2026-100889 (Trusted Domain Project OpenDKIM). CVSS 6.9 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-3855",
      "detail": "RESCORED — CVE-2026-3855 (GitLab). CVSS 3.1 → 6.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-45751",
      "detail": "RESCORED — CVE-2026-45751 (OISF suricata). CVSS 5.9 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-57225",
      "detail": "RESCORED — CVE-2026-57225 (OISF suricata). CVSS 3.3 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-57226",
      "detail": "RESCORED — CVE-2026-57226 (OISF suricata). CVSS 3.7 → 5.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-63448",
      "detail": "RESCORED — CVE-2026-63448 (OISF suricata). CVSS 5.9 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-63449",
      "detail": "RESCORED — CVE-2026-63449 (OISF suricata). CVSS 3.7 → 5.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-63450",
      "detail": "RESCORED — CVE-2026-63450 (OISF suricata). CVSS 3.7 → 5.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-63451",
      "detail": "RESCORED — CVE-2026-63451 (OISF suricata). CVSS 3.3 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-6730",
      "detail": "RESCORED — CVE-2026-6730 (IBM Concert). CVSS 9.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-71855",
      "detail": "RESCORED — CVE-2026-71855 (OISF suricata). CVSS 5.9 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-77246",
      "detail": "RESCORED — CVE-2026-77246 (sooperset mcp-atlassian). CVSS 7.4 → 8.6 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-77272",
      "detail": "RESCORED — CVE-2026-77272 (sooperset mcp-atlassian). CVSS 5.4 → 6.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-77896",
      "detail": "RESCORED — CVE-2026-77896 (Microsoft Windows 10 Version 1607). CVSS 6.5 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-78252",
      "detail": "RESCORED — CVE-2026-78252 (GitLab). CVSS 8.2 → 6.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-78426",
      "detail": "RESCORED — CVE-2026-78426 (SUSE neuvector). CVSS 3.7 → 2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-78427",
      "detail": "RESCORED — CVE-2026-78427 (SUSE github.com/neuvector/neuvector). CVSS 4.3 → 5.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-78428",
      "detail": "RESCORED — CVE-2026-78428 (SUSE neuvector). CVSS 8 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-81884",
      "detail": "RESCORED — CVE-2026-81884 (radareorg radare2). CVSS 2.5 → 3.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-82837",
      "detail": "RESCORED — CVE-2026-82837 (GitLab). CVSS 5.3 → 4.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-93659",
      "detail": "RESCORED — CVE-2026-93659 (concretecms-community-store community_store). CVSS 9.3 → 8.6 (NVD)."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2026-100655",
      "detail": "REJECTED — CVE-2026-100655 (netty). Record withdrawn by the CNA."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2026-100656",
      "detail": "REJECTED — CVE-2026-100656 (netty). Record withdrawn by the CNA."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2026-100657",
      "detail": "REJECTED — CVE-2026-100657 (netty). Record withdrawn by the CNA."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2026-100658",
      "detail": "REJECTED — CVE-2026-100658 (netty). Record withdrawn by the CNA."
    },
    {
      "type": "DISPUTED",
      "cve_id": "CVE-2026-93353",
      "detail": "DISPUTED — CVE-2026-93353 (9001 copyparty). Record marked disputed."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-91043",
      "detail": "PATCH SHIPPED — CVE-2026-91043 (elixir-mint mint). Fixed in mint c7895cb022196c77ec35570c8e873a84393ff4b8."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-92103",
      "detail": "PATCH SHIPPED — CVE-2026-92103 (elixir-mint mint). Fixed in mint 20252ca85065f4d1092aed9ee4ed21841a507dfe."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-93990",
      "detail": "PATCH SHIPPED — CVE-2026-93990 (libexpat). Fixed in libexpat 2.8.5."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-94194",
      "detail": "PATCH SHIPPED — CVE-2026-94194 (elixir-mint mint). Fixed in mint 2ec8b696b5475ecbdaa87c0098957bca339e17c0."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
