{
  "day": "2026-09-29",
  "boundary": "UTC calendar day",
  "published_count": 611,
  "by_severity": {
    "CRITICAL": 70,
    "HIGH": 224,
    "MEDIUM": 169,
    "LOW": 46
  },
  "kev_count": 0,
  "exploit_reference_count": 5,
  "awaiting_enrichment_count": 102,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-101858",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.02055,
      "epss_percentile": 0.80513,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RaspAP",
      "product": "raspap-webgui",
      "cwe": "CWE-77",
      "title": "RaspAP raspap-webgui SSID Processing WiFiManager.php writeWpaSupplicant os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101858"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-102240",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02011,
      "epss_percentile": 0.80091,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netcore",
      "product": "NAP930",
      "cwe": "CWE-77",
      "title": "Netcore NAP930 Network Tools CGI network_tools eval os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102240"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-101859",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.01577,
      "epss_percentile": 0.74497,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RaspAP",
      "product": "raspap-webgui",
      "cwe": "CWE-77",
      "title": "RaspAP raspap-webgui OpenVPN Configuration del_ovpncfg.php escapeshellcmd os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101859"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-102243",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.01158,
      "epss_percentile": 0.6581,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MODSetter",
      "product": "SurfSense",
      "cwe": "CWE-74",
      "title": "MODSetter SurfSense MCP Connector Integration test command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102243"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-8066",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01157,
      "epss_percentile": 0.658,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hitachi Energy",
      "product": "RTU500 series CMU firmware",
      "cwe": "CWE-23",
      "title": "A directory traversal vulnerability in the file upload functionality of Hitachi Energy RTU500 end-of-life versions allows an unauthenticated attacker to write or overwrite arbitrary files on the device file system. Depending on the files affected, successful exploitation could result in unauthorized modification of device data or disruption of the device’s intended operation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8066"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-8065",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00577,
      "epss_percentile": 0.45384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hitachi Energy",
      "product": "RTU500 series CMU firmware",
      "cwe": "CWE-306",
      "title": "An authentication bypass vulnerability in the firmware update endpoint of Hitachi Energy RTU500 end-of-life versions allows an unauthenticated attacker to upload arbitrary firmware through a crafted POST request. Successful exploitation could allow the attacker to modify device functionality or compromise the integrity or availability of the device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8065"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-101860",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00473,
      "epss_percentile": 0.3849,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RaspAP",
      "product": "raspap-webgui",
      "cwe": "CWE-266",
      "title": "RaspAP raspap-webgui sudo Configuration PluginInstaller.php addSudoers privileges management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101860"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-95387",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00454,
      "epss_percentile": 0.36922,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-122",
      "title": "Heap-based Buffer Overflow in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95387"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-7395",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00419,
      "epss_percentile": 0.33703,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hitachi Energy",
      "product": "Asset Suite",
      "cwe": "CWE-306",
      "title": "Asset Suite allows unauthenticated users to access HTTPPublishAdapterTestServlet that can be used for configuration file upload, leading to information disclosure and integrity compromise. The HTTPPublishAdapterTestServlet is specifically meant for testing purposes to be used in a non-production environment.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7395"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-11796",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00419,
      "epss_percentile": 0.33703,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hitachi Energy",
      "product": "Asset Suite",
      "cwe": "CWE-306",
      "title": "Asset Suite allows unauthenticated users to access PropertiesReloadServlet, CacheFlushServlet, MetadataCacheFlushServlet and ResourceBundleReloadServlet, which could result in denial-of-service conditions affecting application availability. These servlets are designed to perform specific functions within production environment depending on how the Asset Suite application is configured.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11796"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-101281",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0041,
      "epss_percentile": 0.32703,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Trusted Domain Project",
      "product": "OpenDMARC",
      "cwe": "CWE-287",
      "title": "Trusted Domain Project OpenDMARC SPF Macro opendmarc_spf.c opendmarc_sp2_find_mailfrom_domain improper authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101281"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-101280",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00402,
      "epss_percentile": 0.31927,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Trusted Domain Project",
      "product": "OpenDMARC",
      "cwe": "CWE-287",
      "title": "Trusted Domain Project OpenDMARC Multi-Record Set opendmarc_policy_query_dmarc authentication spoofing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101280"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-102247",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00393,
      "epss_percentile": 0.30887,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "FastAdmin",
      "cwe": "CWE-250",
      "title": "FastAdmin Database Management database.php unnecessary privileges",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102247"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-95389",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00392,
      "epss_percentile": 0.30703,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-122",
      "title": "Heap-based Buffer Overflow in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95389"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-102245",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00385,
      "epss_percentile": 0.30016,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MODSetter",
      "product": "SurfSense",
      "cwe": "CWE-287",
      "title": "MODSetter SurfSense circleback Endpoint circleback_webhook_route.py missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102245"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-101354",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00384,
      "epss_percentile": 0.29825,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FAST",
      "product": "FAC1203R",
      "cwe": "CWE-119",
      "title": "FAST FAC1203R MmtAtePrase _tWlanTask stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101354"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-102422",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00383,
      "epss_percentile": 0.29703,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "shell-quote",
      "cwe": "CWE-78",
      "title": "shell-quote `quote()` command injection via a line terminator in a token after a `{ comment }` token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102422"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-102248",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00383,
      "epss_percentile": 0.29794,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Rebuild",
      "cwe": "CWE-287",
      "title": "Rebuild Login Endpoint login improper authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102248"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-84739",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00362,
      "epss_percentile": 0.2755,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-79",
      "title": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84739"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-84154",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00355,
      "epss_percentile": 0.26699,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dassault Systèmes",
      "product": "GEOVIA Geospatial Data Manager",
      "cwe": "CWE-94",
      "title": "Code Injection vulnerability affecting GEOVIA Geospatial Data Manager from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84154"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-4523",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00345,
      "epss_percentile": 0.2554,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-862",
      "title": "Missing Authorization in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4523"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-96428",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00342,
      "epss_percentile": 0.25173,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Flowring Technology Corp",
      "product": "Agentflow 4.0",
      "cwe": "CWE-89",
      "title": "Flowring Agentflow 4.0 - SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96428"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-101169",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00334,
      "epss_percentile": 0.24308,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Octopus Deploy",
      "product": "Octopus Server",
      "cwe": "CWE-502",
      "title": "In affected versions of Octopus Server, an authenticated user with permissions to edit an Environment or Project can set specifically crafted JSON content for the object. Insecure deserialization of this content allows the user to execute arbitrary code in the Octopus Server process.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101169"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-10518",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00331,
      "epss_percentile": 0.23748,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-863",
      "title": "Incorrect Authorization in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10518"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-8067",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00324,
      "epss_percentile": 0.23036,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hitachi Energy",
      "product": "RTU500 series CMU firmware",
      "cwe": "CWE-862",
      "title": "An improper authorization vulnerability in the end-of-life versions of RTU500’s web application allows an authenticated user to trigger the RTU500 to reboot through the reset endpoint. Successful exploitation could cause temporary device unavailability and disruption of its intended operation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8067"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-101279",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00324,
      "epss_percentile": 0.23029,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Trusted Domain Project",
      "product": "OpenDMARC",
      "cwe": "CWE-189",
      "title": "Trusted Domain Project OpenDMARC opendmarc_policy.c integer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101279"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-92142",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00313,
      "epss_percentile": 0.2179,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Karaf",
      "cwe": "CWE-862",
      "title": "Apache Karaf: Authorization bypass in JMX MBean lifecycle operations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92142"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-97024",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00309,
      "epss_percentile": 0.21359,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-61",
      "title": "Flatpak: flatpak: arbitrary write in root context via path traversal in deploy directory files/etc",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97024"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-96440",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00292,
      "epss_percentile": 0.19554,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Flowring Technology Corp",
      "product": "Agentflow 4.0",
      "cwe": "CWE-22",
      "title": "Flowring Agentflow 4.0 - Improper Limitation of a Pathname to a Restricted Directory（Path Traversal）",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96440"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-102414",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00284,
      "epss_percentile": 0.18762,
      "kev": false,
      "kev_due_at": null,
      "vendor": "browserify",
      "product": "pbkdf2",
      "cwe": "CWE-400",
      "title": "pbkdf2 rehashes long passwords on every iteration, enabling denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102414"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-102249",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00284,
      "epss_percentile": 0.18786,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "REBUILD",
      "cwe": "CWE-862",
      "title": "REBUILD file-editor-save authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102249"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-102292",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00282,
      "epss_percentile": 0.18565,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coolbeans1212",
      "product": "MateisHomePage-Website",
      "cwe": "CWE-79",
      "title": "coolbeans1212 MateisHomePage-Website users.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102292"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-102293",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00278,
      "epss_percentile": 0.1821,
      "kev": false,
      "kev_due_at": null,
      "vendor": "realjerrytang",
      "product": "tacomall",
      "cwe": "CWE-266",
      "title": "realjerrytang tacomall api-admin Backend ApiMaApplication.java OrgStaffServiceImpl.add improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102293"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-96429",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00277,
      "epss_percentile": 0.18132,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Flowring Technology Corp",
      "product": "Agentflow 4.0",
      "cwe": "CWE-89",
      "title": "Flowring Agentflow 4.0 - SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96429"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-96431",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00275,
      "epss_percentile": 0.17883,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Flowring Technology Corp",
      "product": "Agentflow 4.0",
      "cwe": "CWE-434",
      "title": "Flowring Agentflow 4.0 - Unrestricted Upload of File with Dangerous Type",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96431"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-8937",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.16331,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-862",
      "title": "Missing Authorization in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8937"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-101878",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00258,
      "epss_percentile": 0.15761,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bitwarden",
      "product": "bitwarden server",
      "cwe": "CWE-303",
      "title": "Bitwarden Server 2025.6.0 < 2025.6.0 Authentication Bypass via SSO Identifier Truncation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101878"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-102290",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00249,
      "epss_percentile": 0.14534,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeCanyon",
      "product": "Rocket LMS",
      "cwe": "CWE-79",
      "title": "CodeCanyon Rocket LMS Student Profile Image Upload cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102290"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-97029",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00244,
      "epss_percentile": 0.14074,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-653",
      "title": "Flatpak: flatpak: sandboxed app can signal unsandboxed processes in the same process group",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97029"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-102261",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00244,
      "epss_percentile": 0.14048,
      "kev": false,
      "kev_due_at": null,
      "vendor": "owen2345",
      "product": "Camaleon CMS",
      "cwe": "CWE-285",
      "title": "owen2345 Camaleon CMS Media Crop media_controller.rb crop authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102261"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-76718",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00243,
      "epss_percentile": 0.13898,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise",
      "product": "HPE OneView",
      "cwe": "CWE-79",
      "title": "HPE OneView - Cross-site scripting vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76718"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-97685",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.13347,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LimeSurvey",
      "product": "LimeSurvey",
      "cwe": "CWE-639",
      "title": "LimeSurvey Community Edition 7.3.0 - Cross-survey object authorization bypass in REST survey patch operations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97685"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-102373",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.1339,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GestSup",
      "product": "GestSup",
      "cwe": "CWE-639",
      "title": "GestSup before 3.2.62 Private Ticket Comment Disclosure via threadedit Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102373"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-102244",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00227,
      "epss_percentile": 0.12127,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MODSetter",
      "product": "SurfSense",
      "cwe": "CWE-918",
      "title": "MODSetter SurfSense Document Export Feature editor_routes.py server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102244"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-96430",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00226,
      "epss_percentile": 0.11963,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Flowring Technology Corp",
      "product": "Agentflow 4.0",
      "cwe": "CWE-749",
      "title": "Flowring Agentflow 4.0 - Exposed Dangerous Method or Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96430"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-102241",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.0022,
      "epss_percentile": 0.11284,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netcore",
      "product": "NAP930",
      "cwe": "CWE-320",
      "title": "Netcore NAP930 Backup/Restore backup_common.sh hard-coded key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102241"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-102263",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00218,
      "epss_percentile": 0.11013,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mwasikz",
      "product": "robo-cafe-rms",
      "cwe": "CWE-284",
      "title": "mwasikz robo-cafe-rms manage-food.php unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102263"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-102372",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.10206,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GestSup",
      "product": "GestSup",
      "cwe": "CWE-79",
      "title": "GestSup before 3.2.61 Stored XSS via Email Body in LOGIN IMAP Connector",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102372"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-102374",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.10206,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GestSup",
      "product": "GestSup",
      "cwe": "CWE-79",
      "title": "GestSup before 3.2.62 Stored XSS via Double-Decoded Email Subject in OAuth IMAP Connector",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102374"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-81914",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.08917,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow Google provider",
      "cwe": "CWE-943",
      "title": "Apache Airflow Google provider: Google Drive query injection via unescaped file and folder names",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81914"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-102264",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00191,
      "epss_percentile": 0.07838,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mwasikz",
      "product": "robo-cafe-rms",
      "cwe": "CWE-79",
      "title": "mwasikz robo-cafe-rms Edit Profile Feature update-account.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102264"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-96326",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0019,
      "epss_percentile": 0.07765,
      "kev": false,
      "kev_due_at": null,
      "vendor": "htplugins",
      "product": "HT Contact Form – Drag & Drop Form Builder for WordPress",
      "cwe": "CWE-79",
      "title": "HT Contact Form – Drag & Drop Form Builder for WordPress <= 2.10.2 Unauthenticated Stored Cross-Site Scripting via Rich Text Editor Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96326"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-91048",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00189,
      "epss_percentile": 0.07638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Karaf",
      "cwe": "CWE-862",
      "title": "Apache Karaf: Missing authorization on the jdbc:* shell command scope allows privilege escalation to remote code execution via jdbc:ds-create",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91048"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-96419",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.0741,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-22",
      "title": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96419"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-91012",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00172,
      "epss_percentile": 0.05871,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Karaf",
      "cwe": null,
      "title": "Apache Karaf: Path Traversal in Config Service Allows Manager-to-Admin Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91012"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-91085",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00163,
      "epss_percentile": 0.04885,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Karaf",
      "cwe": "CWE-862",
      "title": "Apache Karaf: config:install missing ACL entry allows privilege escalation to admin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91085"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-95392",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.04295,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-126",
      "title": "Buffer Over-read in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95392"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-96417",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.03661,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-122",
      "title": "Heap-based Buffer Overflow in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96417"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-102474",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00144,
      "epss_percentile": 0.03064,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 6",
      "cwe": "CWE-787",
      "title": "Dash: dash: heap out-of-bounds write in conv_escape via undersized unicode escape reservation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102474"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-95386",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00141,
      "epss_percentile": 0.02811,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-835",
      "title": "Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95386"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-95390",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00141,
      "epss_percentile": 0.02811,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-476",
      "title": "NULL Pointer Dereference in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95390"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-95391",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00141,
      "epss_percentile": 0.02811,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-416",
      "title": "Use After Free in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95391"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-95395",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00141,
      "epss_percentile": 0.02811,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-401",
      "title": "Missing Release of Memory after Effective Lifetime in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95395"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-95388",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0014,
      "epss_percentile": 0.028,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-122",
      "title": "Heap-based Buffer Overflow in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95388"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-96415",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0014,
      "epss_percentile": 0.028,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-121",
      "title": "Stack-based Buffer Overflow in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96415"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-96416",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0014,
      "epss_percentile": 0.02799,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-122",
      "title": "Heap-based Buffer Overflow in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96416"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-96418",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0014,
      "epss_percentile": 0.02799,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-835",
      "title": "Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96418"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-95394",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.02531,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-606",
      "title": "Unchecked Input for Loop Condition in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95394"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-96421",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00134,
      "epss_percentile": 0.02428,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-1325",
      "title": "Improperly Controlled Sequential Memory Allocation in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96421"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-96422",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00134,
      "epss_percentile": 0.02428,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-617",
      "title": "Reachable Assertion in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96422"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-96423",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00134,
      "epss_percentile": 0.02428,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-122",
      "title": "Heap-based Buffer Overflow in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96423"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-101278",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00133,
      "epss_percentile": 0.02359,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Trusted Domain Project",
      "product": "OpenDMARC",
      "cwe": "CWE-345",
      "title": "Trusted Domain Project OpenDMARC PSL Wildcard opendmarc_tld.c : opendmarc_get_tld origin validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101278"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-102473",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.02204,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 6",
      "cwe": "CWE-1333",
      "title": "Dash: dash: super-polynomial backtracking in pmatch when libc fnmatch is disabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102473"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-95393",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02056,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-122",
      "title": "Heap-based Buffer Overflow in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95393"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-96420",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.0174,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-126",
      "title": "Buffer Over-read in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96420"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-86157",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00119,
      "epss_percentile": 0.016,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software",
      "product": "Progress® Telerik® Fiddler® Everywhere",
      "cwe": "CWE-749",
      "title": "Exposure of Privileged IPC Functionality in Progress Telerik Fiddler Everywhere",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86157"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-86158",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00087,
      "epss_percentile": 0.0033,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software",
      "product": "Progress® Telerik® Fiddler® Everywhere",
      "cwe": "CWE-306",
      "title": "Missing Authentication in the local .NET backend of Progress Telerik Fiddler Everywhere",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86158"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-71379",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Toptech Systems",
      "product": "TMS7",
      "cwe": "CWE-552",
      "title": "Toptech TMS7 and TopHAT Files or Directories Accessible to External Parties",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71379"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-96587",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Viidure",
      "product": "Dashcam Android Application",
      "cwe": "CWE-798",
      "title": "Use of Hard-coded Credentials in Viidure Dashcam Android Application",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96587"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-39117",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-94",
      "title": "An issue in AltumCode 66Uptime before v.54.0.0 and 66Uptime ping-servers plugin before v.2.0.0 allows a remote attacker to execute arbitrary code via the index.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39117"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-76721",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Instant ON",
      "cwe": null,
      "title": "Unauthenticated Buffer Overflow Vulnerability leads to Remote Code Execution in HPE Networking Instant ON APs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76721"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-76722",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Instant ON",
      "cwe": null,
      "title": "Uncontrolled Format String Vulnerabilities lead to Remote Code Execution or Denial-of-Service in HPE Networking Instant ON APs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76722"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-77177",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-94",
      "title": "Open GenAI Stack (aka ogx-ai) 2026-06-11, as used in the Meta AI backend for WhatsApp and other products, allows code execution because prompt injection (with Jinja2 template syntax) can be used to achieve server-side expression evaluation without sanitization.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77177"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-79538",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-94",
      "title": "metatool-ai MetaMCP up to and including 2.4.22 is vulnerable to Code Execution in the internal MCP inspector proxy endpoint GET /mcp-proxy/server/stdio (createTransport, STDIO branch, routers/mcp-proxy/server.ts).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79538"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-76723",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Instant ON",
      "cwe": null,
      "title": "Unauthenticated Adjacent Buffer Overflow Vulnerabilities lead to Remote Code Execution in HPE Networking Instant ON APS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76723"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-76724",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Instant ON",
      "cwe": null,
      "title": "Unauthenticated Adjacent Command Injection Vulnerability in HPE Networking Instant ON APs Command Line Interface (CLI) Accessed by the PAPI Protocol",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76724"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-76725",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Instant ON",
      "cwe": null,
      "title": "Authentication Bypass in a Management Protocol of HPE Networking Instant ON APs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76725"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-95277",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Views in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95277"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-95281",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-122",
      "title": "Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95281"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-95283",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-122",
      "title": "Buffer overflow in Tint in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95283"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-95299",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in GPU in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95299"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-95310",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in AdFilter in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95310"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-95311",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-590",
      "title": "Free of non-heap memory in Fonts in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95311"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-95313",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Fullscreen in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95313"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-95318",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-122",
      "title": "Buffer overflow in Video in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95318"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-95325",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in ANGLE in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95325"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-95329",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-787",
      "title": "Out of bounds write in WebGL in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95329"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-95331",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-787",
      "title": "Out of bounds write in ANGLE in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95331"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-95339",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in ServiceWorker in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95339"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-95347",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Updater in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95347"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-95349",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-122",
      "title": "Buffer overflow in WebGL in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95349"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-95350",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-122",
      "title": "Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95350"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-95356",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WindowDialog in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95356"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-95357",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-787",
      "title": "Out of bounds write in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95357"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-100762",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Sandbox escape due to use-after-free in the DOM: Content Processes component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100762"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-100770",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Sandbox escape due to use-after-free in the DOM: Content Processes component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100770"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-100778",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Sandbox escape due to use-after-free in the DOM: Core & HTML component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100778"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-100786",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Sandbox escape due to use-after-free in the Graphics component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100786"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-100800",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Sandbox escape due to use-after-free in the Disability Access APIs component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100800"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-100804",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Sandbox escape due to use-after-free in the Preferences: Backend component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100804"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-100811",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Sandbox escape due to use-after-free in the DOM: Core & HTML component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100811"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-100818",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Sandbox escape due to use-after-free in the Widget: Gtk component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100818"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-100819",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-119",
      "title": "Sandbox escape due to incorrect boundary conditions in the XPCOM component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100819"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-102304",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Passwords in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102304"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-102306",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Bluetooth in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102306"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-102308",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Views in Google Chrome prior to 154.0.8037.92 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102308"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-102309",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in FullScreen in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102309"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-102316",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Views in Google Chrome prior to 154.0.8037.92 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102316"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-102331",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-122",
      "title": "Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102331"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-102425",
      "cvss_base": 9.5,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "balbooa.com",
      "product": "Balbooa Forms extension for Joomla",
      "cwe": "CWE-94",
      "title": "Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode injection in Balbooa Forms < 2.4.3.4",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102425"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-70356",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Toptech Systems",
      "product": "TMS7",
      "cwe": "CWE-434",
      "title": "Toptech TMS7 and TopHAT Unrestricted Upload of File with Dangerous Type",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70356"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-82973",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "psyb0t",
      "product": "docker-mailbox",
      "cwe": "CWE-93",
      "title": "Improper Neutralization of CRLF Sequences ('CRLF Injection') in docker-mailbox",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82973"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-102793",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ziroom",
      "product": "ZHOME A0101",
      "cwe": "CWE-77",
      "title": "Ziroom ZHOME A0101 set_time_zone command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102793"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-102794",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ziroom",
      "product": "ZHOME A0101",
      "cwe": "CWE-77",
      "title": "Ziroom ZHOME A0101 ping command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102794"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2023-54400",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fumasoft",
      "product": "Fumeng Cloud",
      "cwe": "CWE-89",
      "title": "Fumeng Cloud SQL Injection via AjaxMethod.ashx getEmpByname",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-54400"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-7192",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shenzhen Dbit Network Equipment",
      "product": "T-CPE301K 4G Mini WiFi Router",
      "cwe": "CWE-121",
      "title": "Multiple vulnerabilities in the T-CPE301K 4G Mini WiFi Router from Shenzhen Dbit Network Equipment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7192"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-22094",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EVbee",
      "product": "DC 80",
      "cwe": "CWE-1391",
      "title": "Weak root password in EVbee DC 80",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22094"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-85520",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MyPresta",
      "product": "Google Merchant Center Feed",
      "cwe": "CWE-73",
      "title": "Unauthenticated arbitrary file write leading to RCE in gmfeed PrestaShop module",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85520"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-100291",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Anjvision",
      "product": "YSSD-RTMP-H5",
      "cwe": "CWE-1188",
      "title": "Initialization of a resource with an insecure default in Anjvision YSSD-RTMP-H5",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100291"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-102710",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "eclipse-threadx/threadx",
      "cwe": "CWE-269",
      "title": "Attacker model / Preconditions: a loaded `TXM_MODULE_USER_MODE | TXM_MODULE_MEMORY_PROTECTION` module issuing kernel dispatch calls, on a build with `TX_ENABLE_EVENT_TRACE`. A user-mode, memory-protected module can register an arbitrary function pointer as the global trace-full callback. The kernel calls it directly — no validation, no trampoline — from privileged kernel code when the trace buffer wraps. An invalid pointer faults the kernel (DoS). A pointer into the module's own code was observed running with kernel privilege (`CONTROL.nPRIV = 0`), confirmed at runtime with a register capture inside that code.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102710"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-102761",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "NetX Duo",
      "cwe": "CWE-787",
      "title": "NetX Duo's WebSocket client resets the unmasking cursor to the first `NX_PACKET` each time it advances through a chained packet, while the loop's upper bound belongs to the current packet. With the standard contiguous packet-pool layout, a masked server frame split across two packets therefore drives the XOR loop through the first packet's unused payload area and on through the second packet's `NX_PACKET` control block. The four-byte WebSocket masking key controls the bytes written, so the corruption is attacker-chosen rather than incidental.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102761"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-103040",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ModelTC",
      "product": "LightLLM",
      "cwe": "CWE-502",
      "title": "LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Router Profiler RPyC Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103040"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-103041",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ModelTC",
      "product": "LightLLM",
      "cwe": "CWE-502",
      "title": "LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Embed Cache RPyC Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103041"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-53988",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Finsys",
      "product": "dockhand",
      "cwe": "CWE-306",
      "title": "Dockhand < 1.0.40 Unauthenticated Webhook Trigger via Git Webhook Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53988"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-86131",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Fireware OS",
      "cwe": "CWE-295",
      "title": "Fireware OS Code Injection in BOVPN Over TLS Client Allows Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86131"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-102828",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "steveukx",
      "product": "git-js",
      "cwe": "CWE-78",
      "title": "simple-git unsafe-operation guard does not block trailer command configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102828"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-102829",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "steveukx",
      "product": "git-js",
      "cwe": "CWE-78",
      "title": "simple-git: `VISUAL` editor environment variable is omitted from unsafe editor detection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102829"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-84436",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-78",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84436"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-15390",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DENX Software Engineering",
      "product": "Das U-Boot",
      "cwe": "CWE-459",
      "title": "Out-of-bounds write in Das U-Boot",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15390"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-92222",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-918",
      "title": "Joomla! Core - [20260909] - Core - SSRF vectors in various core extensions in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92222"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-97689",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "urllib3",
      "product": "urllib3",
      "cwe": "CWE-770",
      "title": "urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97689"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-102424",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "balbooa.com",
      "product": "Balbooa Forms extension for Joomla",
      "cwe": "CWE-22",
      "title": "Joomla Extension - balbooa.com - Unauthenticated path traversal exfiltrates local files through auto-reply attachments in Balbooa Forms < 2.4.3.4",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102424"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-71971",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "u-boot",
      "product": "u-boot",
      "cwe": "CWE-787",
      "title": "U-Boot before 2026.10-rc3 Out-of-Bounds Write in IP Fragment Reassembly",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71971"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-74220",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "u-boot",
      "product": "u-boot",
      "cwe": "CWE-195",
      "title": "U-Boot before 2026.10-rc5 Buffer Overflow via NFS READ Reply",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74220"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-74221",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "u-boot",
      "product": "u-boot",
      "cwe": "CWE-195",
      "title": "U-Boot before 2026.10-rc5 Buffer Overflow via NFS READLINK",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74221"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-74222",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "u-boot",
      "product": "u-boot",
      "cwe": "CWE-416",
      "title": "U-Boot before 2026.10-rc5 Use-After-Free in lwIP wget Receive Callback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74222"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-82804",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache DolphinScheduler",
      "cwe": "CWE-78",
      "title": "Apache DolphinScheduler: Command Injection in the Alert Script Plugin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82804"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-84421",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DataStage on Cloud Pak for Data",
      "cwe": "CWE-22",
      "title": "DataStage on Cloud Pak for Data has several vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84421"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-87748",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Interprobe Information Technologies Inc.",
      "product": "Qorela DC",
      "cwe": "CWE-862",
      "title": "Privilege Escalation via Account Takeover in Interprobe's Qorela DC",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87748"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-92370",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TeamViewer",
      "product": "Full Client",
      "cwe": "CWE-284",
      "title": "Remote Session Access Control Bypass Leading to Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92370"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-95282",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Platform in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95282"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-95286",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "title": "Type confusion in Bindings in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95286"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-95304",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-787",
      "title": "Out of bounds write in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95304"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-95306",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "title": "Type confusion in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95306"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-95338",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in PDFium in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95338"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-95343",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebAudio in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95343"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-95345",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Actor in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95345"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-95353",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Bindings in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95353"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-95365",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "title": "Type confusion in IndexedDB in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95365"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-95369",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-841",
      "title": "Inappropriate implementation in XML in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95369"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-95373",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95373"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-95380",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "title": "Type confusion in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95380"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-95509",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "qt",
      "product": "Qt for MCUs",
      "cwe": "CWE-125",
      "title": "Out-of-bounds read vulnerability in string formatting impacts Qt for MCUs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95509"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-100757",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Use-after-free in the Widget component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100757"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-100761",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Privilege escalation due to use-after-free in the Graphics: WebGPU component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100761"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-100764",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-119",
      "title": "Privilege escalation due to incorrect boundary conditions in the Graphics: WebGPU component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100764"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-100765",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Use-after-free in the JavaScript: WebAssembly component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100765"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-100767",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Use-after-free in the Networking: Cache component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100767"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-100768",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Use-after-free in the Graphics: WebGPU component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100768"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-100769",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Use-after-free in the JavaScript: WebAssembly component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100769"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-100772",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Use-after-free in the DOM: Core & HTML component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100772"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-100773",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Use-after-free in the Storage: IndexedDB component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100773"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-100774",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Use-after-free in the DOM: Core & HTML component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100774"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-100776",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Use-after-free in the JavaScript: WebAssembly component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100776"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-100777",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Use-after-free in the Graphics: Canvas2D component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100777"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-100779",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Use-after-free in the XSLT component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100779"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-100780",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Use-after-free in the DOM: Core & HTML component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100780"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-100782",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-119",
      "title": "Privilege escalation due to incorrect boundary conditions in the Graphics component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100782"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-100784",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Use-after-free in the Layout: Text and Fonts component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100784"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-100785",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Use-after-free in the DOM: Core & HTML component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100785"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-100789",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Use-after-free in the Graphics: Canvas2D component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100789"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-100790",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Use-after-free in the XSLT component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100790"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-100791",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Use-after-free in the DOM: Core & HTML component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100791"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-100796",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Use-after-free in the JavaScript: WebAssembly component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100796"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-100797",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Privilege escalation due to use-after-free in the Graphics: WebRender component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100797"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-100801",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-269",
      "title": "Privilege escalation in the DLL Services component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100801"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-100807",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-269",
      "title": "Privilege escalation in the DOM: Service Workers component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100807"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-100813",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-763",
      "title": "Invalid pointer in the JavaScript Engine: JIT component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100813"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-100814",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-119",
      "title": "Incorrect boundary conditions in the JavaScript Engine: JIT component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100814"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-100815",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Use-after-free in the CSS Parsing and Computation component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100815"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-100820",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-269",
      "title": "Privilege escalation in the Address Bar component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100820"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-100824",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-269",
      "title": "Privilege escalation in the Places component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100824"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-100825",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Use-after-free in the JavaScript Engine: JIT component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100825"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-100831",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Use-after-free in the DOM: UI Events & Focus Handling component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100831"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-100832",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Use-after-free in the Graphics: Canvas2D component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100832"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-102299",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "title": "Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102299"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-102302",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-121",
      "title": "Buffer overflow in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102302"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-102321",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "title": "Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102321"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-102323",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "title": "Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102323"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-102326",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "title": "Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102326"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-102328",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "title": "Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102328"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-102712",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "NetX Duo",
      "cwe": "CWE-125",
      "title": "On the first DTLS ClientHello, the parser copies a device-claimed session_id length and validates the ciphersuite-list length against the total record length instead of the remaining bytes. An unauthenticated peer drives an OOB source read of up to 255 bytes, and those bytes are echoed verbatim into the outgoing ServerHello, disclosing adjacent process memory over the network. The crash variant fires on the first packet.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102712"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-102713",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "NetX Duo",
      "cwe": "CWE-125",
      "title": "The TFTP server accepts a DATA datagram of any size. The dispatcher rejects datagrams shorter than four bytes (nxd_tftp_server.c:1037) and nothing anywhere checks an upper bound, in particular not against the protocol maximum of 4 + NX_TFTP_FILE_TRANSFER_MAX. Two things follow from that one missing check, both reachable before any authentication because TFTP has none. The handler passes `nx_packet_length - 4` straight to FileX: ```c /* addons/tftp/nxd_tftp_server.c:1863, 1889 */ status = nx_packet_copy(packet_ptr, &temp_ptr, server_ptr -> nx_tftp_server_packet_pool_ptr, NX_WAIT_FOREVER); ... fx_file_write(&(client_request_ptr -> nx_tftp_client_request_file), packet_ptr -> nx_packet_prepend_ptr + 4, packet_ptr -> nx_packet_length - 4); ``` `nx_packet_length` is the length of a chain, not of one contiguous buffer, so FileX copies past the end of the first packet: ``` ERROR: AddressSanitizer: heap-buffer-overflow READ of size 1280 at 0x621000001108 thread T5 #0 __interceptor_memcpy #1 _fx_utility_memory_copy filex/common/src/fx_utility_memory_copy.c:78 0x621000001108 is 0 bytes to the right of 4104-byte region ``` Those bytes are written into the file the attacker is uploading, and a TFTP read request hands them back, so this is a memory disclosure with a convenient retrieval channel. The same datagram also wedges the server. `nx_packet_copy` at :1863 needs ceil(nx_packet_length / pool_payload) packets and asks for them with NX_WAIT_FOREVER, so when the attacker sizes the datagram beyond what the pool holds, the server thread suspends and never returns. A liveness probe after one such datagram times out with the pool at 0 of 12 packets and the server thread suspended, and no later client is served. Reject `nx_packet_length > 4 + NX_TFTP_FILE_TRANSFER_MAX` in the DATA branch before either call, and use a bounded wait rather than NX_WAIT_FOREVER for the copy.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102713"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2015-20122",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Yonyou",
      "product": "A6 OA",
      "cwe": "CWE-89",
      "title": "Seeyon A6 OA Unauthenticated SQL Injection via downloadAtt.jsp",
      "url": "https://www.cve.org/CVERecord?id=CVE-2015-20122"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2022-51019",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "akaunting",
      "product": "akaunting",
      "cwe": "CWE-78",
      "title": "Akaunting before 2.1.31 OS Command Injection via app alias",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-51019"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-4034",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tibco",
      "product": "Administrator",
      "cwe": "CWE-74",
      "title": "TIBCO Administrator Injection Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4034"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-61519",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Liberu Software",
      "product": "Liberu CRM",
      "cwe": "CWE-863",
      "title": "Liberu CRM 0.9.1 < 10.0.0 Broken Access Control via TeamPolicy::addTeamMember()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61519"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-68911",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nicotine-plus",
      "product": "nicotine-plus",
      "cwe": "CWE-409",
      "title": "Nicotine+: Decompression of peer messages can exhaust available memory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68911"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-81433",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Fireware OS",
      "cwe": "CWE-120",
      "title": "Fireware OS Pre-Authentication Stack Buffer Overflow in fingerd Allows Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81433"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-86104",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Fireware OS",
      "cwe": "CWE-400",
      "title": "Fireware OS Resource Exhaustion in Login Process Allows Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86104"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-94204",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Viidure",
      "product": "Dashcam Android Application",
      "cwe": "CWE-732",
      "title": "Incorrect Permission Assignment for Critical Resource in Viidure Dashcam Android Application",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94204"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-100292",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Anjvision",
      "product": "YSSD-RTMP-H5",
      "cwe": "CWE-78",
      "title": "Improper neutralization of special elements used in an OS command ('OS command injection') in Anjvision YSSD-RTMP-H5",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100292"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-100293",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Anjvision",
      "product": "YSSD-RTMP-H5",
      "cwe": "CWE-347",
      "title": "Improper verification of cryptographic signature in Anjvision YSSD-RTMP-H5",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100293"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-100294",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Anjvision",
      "product": "YSSD-RTMP-H5",
      "cwe": "CWE-798",
      "title": "Use of Hard-coded Credentials in Anjvision YSSD-RTMP-H5",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100294"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-100298",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Anjvision",
      "product": "YSSD-RTMP-H5",
      "cwe": "CWE-522",
      "title": "Insufficiently Protected Credentials in Anjvision YSSD-RTMP-H5",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100298"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-102253",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "esnet",
      "product": "iperf3",
      "cwe": "CWE-835",
      "title": "iperf3 < 3.22 UDP Receive Worker Infinite Loop DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102253"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-102634",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sgl-project",
      "product": "sglang",
      "cwe": "CWE-694",
      "title": "SGLang through 0.5.20 Denial of Service via Duplicate bootstrap_room",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102634"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-102716",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "eclipse-threadx/netxduo",
      "cwe": "CWE-401",
      "title": "An unauthenticated client can drain the RTSP server's packet pool with a couple of dozen requests that carry a Session header the parser cannot convert. The Session branch returns the raw NetX error code instead of an RTSP status code: ```c /* addons/rtsp/nx_rtsp_server.c:2754 */ status = _nx_utility_string_to_uint(field_value_ptr, field_value_length, &session_id); if (status) { return(status); /* NX_INVALID_PARAMETERS / NX_SIZE_ERROR / NX_OVERFLOW */ } ``` Every other branch of the same function maps its failure to an RTSP status first. The CSeq branch eighteen lines earlier does exactly that (line 2736 returns NX_RTSP_STATUS_CODE_BAD_REQUEST). The raw code then reaches `_nx_rtsp_server_error_response_send` (nx_rtsp_server.c:1234), which does not recognise it, takes a path that returns without releasing the response packet it already allocated, and the block never goes back to the pool. Six requests with an empty Session header against a 22 packet pool: ``` valid requests: after request 6: pool available = 21, AFTER = 22 / 22 malformed requests: after request 6: pool available = 16, AFTER = 17 / 22 ``` One block per request, not returned when the client disconnects. Twenty six requests take the pool to zero and the server starts failing allocations, after which it serves nobody. If the pool is shared with the rest of the application, as it is in the shipped sample, the rest of the stack stops with it. Convert the `_nx_utility_string_to_uint` failure in the Session branch into NX_RTSP_STATUS_CODE_BAD_REQUEST the way the CSeq branch does, and release the response packet on every exit path of `_nx_rtsp_server_error_response_send`.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102716"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-102718",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "NetX Duo",
      "cwe": "CWE-125",
      "title": "hey, `_nx_snmp_utility_object_id_get` in the NetX Duo SNMP addon does not validate the claimed OID data length against the actual buffer size when the OID uses BER multibyte length encoding, so a remote attacker can send a crafted SNMP packet with a multibyte OID length larger than the available buffer, causing the parser to read past the packet buffer boundary into adjacent heap memory. the OOB bytes are decoded as OID component values and written into the agents internal OID string buffer, corrupting agent state. on systems with memory protection the OOB read poses the risk of crashing the SNMP agent thread, causing denial of service. on bare metal embedded systems without memory protection the read silently succeeds and corrupts the agents internal state with heap data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102718"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-102810",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rochacbruno",
      "product": "marmite",
      "cwe": "CWE-22",
      "title": "Marmite through 0.4.2 Path Traversal via Development Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102810"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-102811",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rochacbruno",
      "product": "marmite",
      "cwe": "CWE-306",
      "title": "Marmite through 0.4.2 Unauthenticated API Access via Development Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102811"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-103042",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ModelTC",
      "product": "LightLLM",
      "cwe": "CWE-770",
      "title": "LightLLM through 1.2.0 Unauthenticated Memory Exhaustion via NCCL Control Channel set_value",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103042"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-103043",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "alexcorvi",
      "product": "anchorme",
      "cwe": "CWE-1333",
      "title": "anchorme through 3.0.8 Regular Expression Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103043"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-7193",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shenzhen Dbit Network Equipment",
      "product": "T-CPE301K 4G Mini WiFi Router",
      "cwe": "CWE-798",
      "title": "Multiple vulnerabilities in the T-CPE301K 4G Mini WiFi Router from Shenzhen Dbit Network Equipment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7193"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-18145",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Fireware OS",
      "cwe": "CWE-121",
      "title": "Fireware OS Stack-based Buffer Overflow in spamd Allows Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18145"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-101127",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "balbooa.com",
      "product": "Balbooa Forms extension for Joomla",
      "cwe": "CWE-79",
      "title": "Joomla Extension - balbooa.com - Unauthenticated upload filename stored XSS in Balbooa Forms < 2.4.3.4",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101127"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-102242",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "MCP Toolbox for Databases",
      "cwe": "CWE-22",
      "title": "Path Traversal via Symlink Following in allowedLocalRoots in MCP Toolbox for Databases",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102242"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-102317",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-269",
      "title": "Improper privilege management in Mojo in Google Chrome on on Windows prior to 154.0.8037.92 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102317"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-102360",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dmonad",
      "product": "lib0",
      "cwe": "CWE-125",
      "title": "lib0 `readUint8Array` performs an unbounded read past the end of the decoder’s view, disclosing adjacent process memory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102360"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-102521",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dmonad",
      "product": "lib0",
      "cwe": "CWE-125",
      "title": "lib0 `readFromDataView` out-of-bounds read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102521"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-102556",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-843",
      "title": "Libsoup: libsoup: heap buffer overflow from websocket pong signal type confusion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102556"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-102557",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-125",
      "title": "Libsoup: libsoup: heap buffer overflow during websocket message reassembly",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102557"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-102558",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-125",
      "title": "Libsoup: libsoup: heap buffer overflow during websocket receive-buffer growth",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102558"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-102559",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-125",
      "title": "Libsoup: libsoup: heap buffer overflow during websocket client-frame masking",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102559"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-102560",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-125",
      "title": "Libsoup: libsoup: heap buffer overflow during outgoing permessage-deflate buffer growth",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102560"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-102730",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "eclipse-threadx/levelx(NAND driver)",
      "cwe": "CWE-787",
      "title": "Mounting an attacker-controlled NAND flash image (`lx_nand_flash_open()`) triggers an unbounded out-of-bounds heap **write** in LevelX's NAND flash-translation-layer metadata parser that overwrites a driver function pointer in the control block, giving a demonstrated control-flow hijack — RIP set to a full 8-byte attacker-chosen value (register-verified). Two accompanying OOB reads. All reproduced verbatim under ASan at HEAD `9f1cfdc`. (The affected metadata-parser header states \"Some portions generated by Copilot (Sonnet 4.6)\" — an AI-generated parser with an unchecked on-flash count.)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102730"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-102876",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "surrealdb",
      "product": "surrealdb",
      "cwe": "CWE-639",
      "title": "SurrealDB before 3.3.0 Cross-Tenant Access via Headers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102876"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-102878",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hangwin",
      "product": "mcp-chrome-bridge",
      "cwe": "CWE-346",
      "title": "mcp-chrome-bridge through 1.0.31 CORS Origin Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102878"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-63713",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Toptech Systems",
      "product": "TMS7",
      "cwe": "CWE-89",
      "title": "Toptech TMS7 and TopHAT SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63713"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-68068",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Toptech Systems",
      "product": "TMS7",
      "cwe": "CWE-89",
      "title": "Toptech TMS7 and TopHAT SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68068"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-68954",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Toptech Systems",
      "product": "TMS7",
      "cwe": "CWE-89",
      "title": "Toptech TMS7 and TopHAT SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68954"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-72507",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Toptech Systems",
      "product": "TMS7",
      "cwe": "CWE-89",
      "title": "Toptech TMS7 and TopHAT SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72507"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-72510",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Toptech Systems",
      "product": "TMS7",
      "cwe": "CWE-89",
      "title": "Toptech TMS7 and TopHAT SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72510"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-86035",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WeblateOrg",
      "product": "weblate",
      "cwe": "CWE-78",
      "title": "Weblate: Mercurial argument injection via repository filenames allows authenticated command execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86035"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-102566",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenNMT",
      "product": "CTranslate2",
      "cwe": "CWE-787",
      "title": "CTranslate2 before 4.8.1 Heap Buffer Overflow via model.bin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102566"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-102697",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ollama",
      "product": "ollama",
      "cwe": "CWE-863",
      "title": "Ollama 0.14.0 before 0.31.2 Experimental Agent Bash Approval Bypass via Prefix-Based Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102697"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-102757",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "ThreadX",
      "cwe": "CWE-125",
      "title": "An unprivileged, memory-protected ThreadX module can have the kernel read and write memory at addresses of its choosing, in privileged mode, and can use that to clear the MPU enable bit and remove its own isolation boundary. The Module Manager decided whether a privileged service could dereference an object address a module named by asking only whether that address fell outside the module. The manager's object pool is outside every module, so the test was satisfied by an address shifted into the interior of one of the module's own privileged allocations, which denotes no object at all. The bytes such an address presents as a control block are bytes the module put there through ordinary create and set services, so the control block ID at the front of them could be made to read as any type the module chose, and the `_txe_` layer's ID test then agreed. The reported chain uses that to reach a privileged `memset` across an attacker-chosen range.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102757"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-102792",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ziroom",
      "product": "ZHOME A0101",
      "cwe": "CWE-74",
      "title": "Ziroom ZHOME A0101 set_syslog command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102792"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-102875",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "videolan",
      "product": "vlc",
      "cwe": "CWE-22",
      "title": "VLC media player before 3.0.24 Path Traversal via skins2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102875"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-100308",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "gluonts",
      "cwe": "CWE-470",
      "title": "GluonTS arbitrary command execution during model deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100308"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-102709",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "ThreadX",
      "cwe": "CWE-200",
      "title": "Improper validation of non-secure (NS) pointers in multiple TrustZone-M non-secure callable (NSC) entry functions allows an attacker executing in the non-secure world to supply pointers to secure memory. The secure firmware subsequently dereferences these attacker-controlled pointers without verifying that they reference non-secure memory, resulting in unintended disclosure of secure memory contents. This violates the isolation guarantees provided by Arm TrustZone-M and can be leveraged as a memory disclosure or corruption primitive that may enable recovery of sensitive cryptographic material.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102709"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-95274",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-116",
      "title": "Improper output encoding in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95274"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-95276",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Improper input validation in Themes in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code inside the sandbox via crafted network traffic. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95276"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-95319",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Printing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95319"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-95322",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-787",
      "title": "Out of bounds write in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95322"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-95334",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-706",
      "title": "Incorrect reference resolution in WebProtect in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95334"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-95335",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in HID in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95335"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-95341",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Improper input validation in Desktop in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95341"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-95348",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Bluetooth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95348"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-95351",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Views in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95351"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-95354",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Verifier in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95354"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-95355",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in Navigation in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95355"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-95372",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Chromecast in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95372"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-95381",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Improper input validation in Printing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95381"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-96274",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Baicells",
      "product": "Nova 430H eNodeB  (model pBS3101SH)",
      "cwe": "CWE-248",
      "title": "Uncaught exception in Baicells Nova 430H",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96274"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-102301",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-787",
      "title": "Out of bounds write in GPU in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102301"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-102324",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in PictureInPicture in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102324"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-102676",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "electron",
      "product": "electron",
      "cwe": "CWE-269",
      "title": "Electron: <webview> can enable Node.js integration in Web Workers despite embedder restrictions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102676"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-102760",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "NetX Duo",
      "cwe": "CWE-416",
      "title": "When NetX Secure is built with `NX_SECURE_KEY_CLEAR`, every TLS record sent on an active session is wiped after it has been handed to TCP. By then the TCP layer owns the packet chain and may already have released it to the packet pool. The wipe therefore writes zeros into packets that are free or in use by another thread, and when a reused packet's pointers no longer describe the old data, the length of the wipe underflows and it runs past the end of the packet pool.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102760"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-13224",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Fireware OS",
      "cwe": "CWE-22",
      "title": "Fireware OS Path Traversal in WebUI Management Agent Allows Arbitrary Local File Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13224"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-76719",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise",
      "product": "HPE OneView",
      "cwe": "CWE-79",
      "title": "HPE OneView - Cross-site scripting vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76719"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-84782",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSSL",
      "product": "OpenSSL",
      "cwe": "CWE-125",
      "title": "DTLS Retransmits Handshake Messages From a Stale Buffer Offset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84782"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-86128",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Fireware OS",
      "cwe": "CWE-476",
      "title": "Fireware OS NULL Pointer Dereference in NetFlow IPv6 Traffic Processing Allows Remote Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86128"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-86132",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Fireware OS",
      "cwe": "CWE-191",
      "title": "Fireware OS Pre-Authentication Integer Underflow in iked Allows Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86132"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-86133",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Fireware OS",
      "cwe": "CWE-1284",
      "title": "Fireware OS Pre-Authentication Integer Underflow in iked Allows Remote Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86133"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-92227",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-287",
      "title": "Joomla! Core - [20260914] - Core - MFA Authentication Bypass through rememberme cookies in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92227"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-102555",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-125",
      "title": "Libsoup: libsoup: heap buffer overflow via uninitialized length in data-uri base64 decoding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102555"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-102633",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libexpat",
      "product": "libexpat",
      "cwe": "CWE-190",
      "title": "libexpat 2.7.2 through 2.8.5 Integer Overflow in expat_realloc",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102633"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-102673",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "electron",
      "product": "electron",
      "cwe": "CWE-346",
      "title": "Electron drops inherited HTML sandbox restrictions for popups opened through OpenURLFromTab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102673"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-102674",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "electron",
      "product": "electron",
      "cwe": "CWE-266",
      "title": "Electron: Windows opened from a sandboxed top-level document do not inherit its sandbox restrictions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102674"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-102762",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "NetX Duo",
      "cwe": "CWE-401",
      "title": "The NetX Duo MQTT client leaks the packet carrying a malformed PUBLISH message. Each malformed PUBLISH costs one packet, or one chain of packets, from the network driver's receive pool, and nothing returns it. A peer that can deliver a few dozen such messages exhausts the pool and stops all inbound network traffic on the device until it is rebooted.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102762"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-76726",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Instant ON",
      "cwe": null,
      "title": "Authentication Bypass Leading to Unauthorized Network Access in HPE Networking Instant ON API Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76726"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-84842",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-22",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84842"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-95333",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Metrics in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95333"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-102826",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "steveukx",
      "product": "git-js",
      "cwe": "CWE-77",
      "title": "simple-git allows command execution through unblocked Git configuration includes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102826"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-102827",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "steveukx",
      "product": "git-js",
      "cwe": "CWE-77",
      "title": "simple-git: unsafe-operations plugin bypass via git long-option abbreviation (--receive-p/--exe) -> command execution (residual of CVE-2026-28291)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102827"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-102831",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jupyterlab",
      "product": "jupyterlab",
      "cwe": "CWE-79",
      "title": "JupyterLab: Cross-site scripting (XSS) in JupyterLab via notebook cells pasted from the system clipboard",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102831"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-19743",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TeamViewer",
      "product": "Full Client",
      "cwe": "CWE-22",
      "title": "Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in TeamViewer Desktop Clients",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19743"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-65102",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "DeepStream",
      "cwe": "CWE-190",
      "title": "NVIDIA DeepStream contains a vulnerability where an attacker could cause an integer overflow by supplying crafted tensor dimensions in a YAML configuration file. A successful exploit of this vulnerability might lead to denial of service, information disclosure, data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65102"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-73598",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway (SCG) Policy Manager",
      "cwe": "CWE-732",
      "title": "Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73598"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-84414",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-732",
      "title": "IBM i is Affected By An Incorrect Permission Assignment Vulnerability in Network Authentication Service []",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84414"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-92368",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TeamViewer",
      "product": "Full Client",
      "cwe": "CWE-122",
      "title": "Heap-Based Buffer Overflow in TeamViewer Session Recording Playback Leads to Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92368"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-95298",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Browser in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95298"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-95315",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Aura in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95315"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-102437",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "esengine",
      "product": "DeepSeek-Reasonix",
      "cwe": "CWE-78",
      "title": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in DeepSeek-Reasonix",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102437"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-102677",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "electron",
      "product": "electron",
      "cwe": "CWE-20",
      "title": "Electron: Sandboxed preload code cache can be poisoned by a compromised renderer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102677"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-102925",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pypa",
      "product": "virtualenv",
      "cwe": "CWE-78",
      "title": "virtualenv bash and fish activation scripts execute commands embedded in paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102925"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-84409",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lantronix",
      "product": "G520 Series",
      "cwe": "CWE-79",
      "title": "Lantronix G520 Series Cellular Gateway Cross-site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84409"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-91191",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lantronix",
      "product": "G520 Series",
      "cwe": "CWE-347",
      "title": "Lantronix G520 Series Cellular Gateway Improper Verification of Cryptographic Signature",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91191"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-102930",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pypa",
      "product": "virtualenv",
      "cwe": "CWE-494",
      "title": "virtualenv: Downloaded seed wheels (pip/setuptools) are not integrity-checked before use",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102930"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-97687",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "urllib3",
      "product": "urllib3",
      "cwe": "CWE-295",
      "title": "urllib3: HTTPS proxy TLS configuration may be ignored or overridden",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97687"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-13046",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Fireware OS",
      "cwe": "CWE-502",
      "title": "Fireware OS Deserialization of Untrusted Data in samld Allows Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13046"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-63209",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "klauspost",
      "product": "compress",
      "cwe": "CWE-190",
      "title": "Integer Overflow or Wraparound and Out-of-bounds Write in compress",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63209"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-71302",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Toptech Systems",
      "product": "TMS7",
      "cwe": "CWE-384",
      "title": "Toptech TMS7 and TopHAT Session Fixation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71302"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-72897",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSSL",
      "product": "OpenSSL",
      "cwe": "CWE-787",
      "title": "Out-of-Bounds Access After SSL_set_SSL_CTX() During a Handshake",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72897"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-84440",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-78",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84440"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-84783",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSSL",
      "product": "OpenSSL",
      "cwe": "CWE-416",
      "title": "Use-After-Free in X.509 Extension Cache Under Concurrent Use",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84783"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-84784",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSSL",
      "product": "OpenSSL",
      "cwe": "CWE-770",
      "title": "QUIC: Unbounded RETIRE_CONNECTION_ID Backlog",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84784"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-86450",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Parla Auto Automotive Trading Limited Company",
      "product": "DetaWix Mobile Web Portal",
      "cwe": "CWE-201",
      "title": "Sensitive Data Exposure in Parla Auto's DetaWix Mobile Web Portal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86450"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-95280",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-362",
      "title": "Race condition in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95280"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-100805",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-362",
      "title": "Race condition, use-after-free in the Audio/Video component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100805"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-102327",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in WebView in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102327"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-102495",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache XMLSchema",
      "cwe": "CWE-674",
      "title": "Apache XMLSchema: Denial of service through unbounded recursion when resolving schema imports and includes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102495"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-102496",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache XMLSchema",
      "cwe": "CWE-674",
      "title": "Apache XMLSchema: Denial of service through deeply nested schema structures",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102496"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-102497",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache XMLSchema",
      "cwe": "CWE-674",
      "title": "Apache XMLSchema: Denial of service through cyclic schema definitions in the schema walker",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102497"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-102600",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "socketio",
      "product": "socket.io",
      "cwe": "CWE-20",
      "title": "Socket.IO: Prototype Pollution via Unsafe Client Session Lookup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102600"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-102823",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eugeny",
      "product": "russh",
      "cwe": "CWE-20",
      "title": "russh: Client-side channel-scoped Handler callbacks fire for channel IDs the client never opened",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102823"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-102675",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "electron",
      "product": "electron",
      "cwe": "CWE-346",
      "title": "Electron: File and HTTP protocol handlers allow cross-origin reads without corsEnabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102675"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-92369",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TeamViewer",
      "product": "Full Client",
      "cwe": "CWE-367",
      "title": "Time-of-check Time-of-use (TOCTOU) Race Condition in TeamViewer Windows Installer Rollback Mechanism Leads to Local Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92369"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-102937",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pypa",
      "product": "virtualenv",
      "cwe": "CWE-78",
      "title": "virtualenv: Command injection via --prompt in activate.bat (batch activator)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102937"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-76727",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Instant ON",
      "cwe": null,
      "title": "Authenticated Command Injection Vulnerabilities in HPE Networking Instant ON",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76727"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-76728",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Instant ON",
      "cwe": null,
      "title": "Authenticated Server-Side Request Forgery Leading to Remote Code Execution in HPE Networking Instant ON APs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76728"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-84422",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-78",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84422"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-86101",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Fireware OS",
      "cwe": "CWE-285",
      "title": "Fireware OS Authorization Bypass in SAML Login Allows Unauthorized SSLVPN Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86101"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-93853",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EnterpriseDB",
      "product": "Barman",
      "cwe": "CWE-283",
      "title": "Barman snapshot backup deletion trusts unverified backup catalog metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93853"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-100296",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Anjvision",
      "product": "YSSD-RTMP-H5",
      "cwe": "CWE-754",
      "title": "Improper Check for Unusual or Exceptional Conditions in Anjvision YSSD-RTMP-H5",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100296"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-18105",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Fireware OS",
      "cwe": "CWE-400",
      "title": "Fireware OS Uncontrolled Resource Consumption in Diagnostic Tasks Allows Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18105"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-74225",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "u-boot",
      "product": "u-boot",
      "cwe": "CWE-787",
      "title": "U-Boot before 2026.10-rc5 Out-of-Bounds Write via DHCPv6",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74225"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-86136",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Fireware OS",
      "cwe": "CWE-22",
      "title": "Fireware OS Missing Authorization in wgagent Management API Allows Denial of Service - Variant A",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86136"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-90441",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Fireware OS",
      "cwe": "CWE-200",
      "title": "Fireware OS Missing Authorization in wgagent Management API Allows Denial of Service - Variant B",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90441"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-92231",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-79",
      "title": "Joomla! Core - [20260915] - Core - XSS filter bypass in InputFilter via HTML5 entity decode mismatch in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92231"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-92232",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-79",
      "title": "Joomla! Core - [20260916] - Core - XSS filter bypass in InputFilter via whitespace characters in HTML data URIs in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92232"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-95520",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-787",
      "title": "Rpm: rpm: integer overflow in iterreadarchivenext() leads to heap-based buffer overflow when parsing untrusted rpm packages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95520"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-102639",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MobilityDB",
      "product": "MobilityDB",
      "cwe": "CWE-195",
      "title": "MobilityDB through 1.3.0 Out-of-bounds Read DoS via WKB Deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102639"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-102714",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "NetX Duo",
      "cwe": "CWE-125",
      "title": "`_nx_icmpv6_validate_options()` scans the option area with `while (length > 2)` (`common/src/nx_icmpv6_validate_options.c:79`). An area whose size leaves a one- or two-byte residue exits the loop with that tail unexamined; the residue is not negative, so the function returns `NX_SUCCESS`. Its zero-length rejection never sees those bytes. Every consumer then re-walks the same area, reading a two-byte option header at the residue and subtracting `nx_icmpv6_option_length << 3` with no zero check and no remaining-length check. Three outcomes follow, selected by bytes the attacker controls. **Zero length byte.** The walker subtracts zero and advances zero. All four handlers loop forever — `_nx_icmpv6_process_ra` (`nx_icmpv6_process_ra.c:245, :528`), `_nx_icmpv6_process_ns` (`:251, :329`), `_nx_icmpv6_process_na` (`:147, :156`) and `_nx_icmpv6_process_redirect` (`:247, :350`). The walk runs in the IP thread, which is the highest-priority thread and does not yield inside the loop, so the system stops until a watchdog reset and the frame can be replayed after each one. **Non-zero length byte on a short residue.** The three unsigned counters underflow — `2 - 8` becomes `0xFFFFFFFA` — and the walk continues past the packet buffer, reading until it faults or meets a zero length byte and freezes. The Router Advertisement counter is signed and exits cleanly in this case. **One-byte residue.** The walker reads a two-byte option header, over-reading one byte. During a runaway walk, stray bytes parsing as a link-layer address option are copied into the neighbor cache (`nx_icmpv6_process_ns.c:280, :293`) and subsequently used as the destination MAC for frames to that neighbour, placing off-packet memory on the link. Confirmed by inspection, not reproduced.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102714"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-102715",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "eclipse-threadx/netxduo",
      "cwe": "CWE-787",
      "title": "mDNS string-cache lookup matches on slot size, so a peer name aliases a shorter one and the response encoder writes past the packet",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102715"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-102808",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PX4",
      "product": "PX4-Autopilot",
      "cwe": "CWE-476",
      "title": "PX4 Autopilot through 1.17.0 NULL Pointer Dereference via sd_stress",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102808"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-102809",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PX4",
      "product": "PX4-Autopilot",
      "cwe": "CWE-789",
      "title": "PX4 Autopilot through 1.17.0 Stack Exhaustion via tests file2 Command",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102809"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-19547",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Artifex Software Inc.",
      "product": "Ghostscript",
      "cwe": "CWE-426",
      "title": "Local Privilege Escalation in Ghostscript for Windows",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19547"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-90913",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-284",
      "title": "Joomla! Core - [20260903] - Core - Improper ACL checks for access level webservice endpoints in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90913"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-90915",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-22",
      "title": "Joomla! Core - [20260905] - Core - Arbitrary directory deletion via cache purge action in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90915"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-92226",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-284",
      "title": "Joomla! Core - [20260913] - Core - Improper ACL checks for varous webservice edit tasks in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92226"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-92371",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TeamViewer",
      "product": "Full Client",
      "cwe": "CWE-59",
      "title": "Local Privilege Escalation via Improper Link Resolution in Cloud Session Recording",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92371"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-100299",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Anjvision",
      "product": "YSSD-RTMP-H5",
      "cwe": "CWE-1391",
      "title": "Use of Weak Credentials in Anjvision YSSD-RTMP-H5",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100299"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-102569",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MacWarrior",
      "product": "clipbucket-v5",
      "cwe": "CWE-89",
      "title": "ClipBucket v5 through 5.5.3-#197 SQL Injection via videoid Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102569"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-102570",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MacWarrior",
      "product": "clipbucket-v5",
      "cwe": "CWE-89",
      "title": "ClipBucket v5 through 5.5.3-#197 SQL Injection via language_id Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102570"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2026-41875",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSolution",
      "product": "Quick.Cart",
      "cwe": "CWE-352",
      "title": "Cross-Site Request Forgery in admin panel of Quick.Cart",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41875"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-90907",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-639",
      "title": "Joomla! Core - [20260902] - Core - Unauthorized user account creation via profile.save controller in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90907"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-90917",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-284",
      "title": "Joomla! Core - [20260907] - Core - Improper ACL checks in outputs for tagged items in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90917"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-90918",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-79",
      "title": "Joomla! Core - [20260908] - Core - XSS in HTML Mail Templates in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90918"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-97688",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "urllib3",
      "product": "urllib3",
      "cwe": "CWE-835",
      "title": "urllib3: Chunked Deflate streaming can enter an infinite loop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97688"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-100297",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Anjvision",
      "product": "YSSD-RTMP-H5",
      "cwe": "CWE-918",
      "title": "Server-Side request forgery (SSRF) in Anjvision YSSD-RTMP-H5",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100297"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2026-101112",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "balbooa.com",
      "product": "Balbooa Forms extension for Joomla",
      "cwe": "CWE-639",
      "title": "Joomla Extension - balbooa.com - Unauthorized Deletion of Attachments in Balbooa Forms < 2.4.3.4",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101112"
    },
    {
      "rank": 354,
      "cve_id": "CVE-2026-101126",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "balbooa.com",
      "product": "Balbooa Forms extension for Joomla",
      "cwe": "CWE-22",
      "title": "Joomla Extension - balbooa.com - File meta data tampering in Balbooa Forms < 2.4.3.4",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101126"
    },
    {
      "rank": 355,
      "cve_id": "CVE-2026-102252",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "OSV-SCALIBR",
      "cwe": "CWE-22",
      "title": "Path Traversal in VMDK Extractor in OSV-SCALIBR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102252"
    },
    {
      "rank": 356,
      "cve_id": "CVE-2026-102567",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenNMT",
      "product": "CTranslate2",
      "cwe": "CWE-125",
      "title": "CTranslate2 before 4.8.1 Out-of-Bounds Read via Model Deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102567"
    },
    {
      "rank": 357,
      "cve_id": "CVE-2026-102721",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "NetX Duo",
      "cwe": "CWE-125",
      "title": "A TFTP server that answers with a short ERROR packet makes the client read up to 64 bytes past the received datagram. Each receive path checks only that the datagram is at least four bytes long (nxd_tftp_client.c:1229, 1521, 1984). When the opcode is NX_TFTP_CODE_ERROR the message string is copied with a loop whose only limits are the destination buffer and a NUL byte: ```c /* addons/tftp/nxd_tftp_client.c:1769 */ for (i = 0; (i < (sizeof(tftp_client_ptr -> nx_tftp_client_error_string) - 1)) && (*buffer_ptr); i++) ``` Nothing compares `buffer_ptr` against `nx_packet_append_ptr`. An ERROR packet that carries no terminating NUL, which a server controls completely, walks the loop off the end of the packet until it happens to meet a zero byte or fills the 64 byte destination. ``` ERROR: AddressSanitizer: heap-buffer-overflow READ of size 1 at 0x60d0000000c8 thread T4 #0 _nxd_tftp_client_file_read addons/tftp/nxd_tftp_client.c:1769 0x60d0000000c8 is 0 bytes to the right of 136-byte region ``` The open path has the same loop at :1327 and reports the same way. What is read lands in `nx_tftp_client_error_string`, which the application is expected to display or log, so adjacent packet pool memory ends up in whatever the device does with the error text. Add `(buffer_ptr < packet_ptr -> nx_packet_append_ptr)` to the loop condition in all three paths.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102721"
    },
    {
      "rank": 358,
      "cve_id": "CVE-2026-102722",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "NetX Duo",
      "cwe": "CWE-918",
      "title": "In the IPv4 PASV path, the FTP Client accepts whatever address was sent in the server's `227` reply. Validation only covers the parse and the non-zero values, thus a malicious server can name any address and direct the Client there.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102722"
    },
    {
      "rank": 359,
      "cve_id": "CVE-2025-33207",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "BlueField GA",
      "cwe": "CWE-1262",
      "title": "NVIDIA ConnectX and Bluefield contain a vulnerability in a control register, where a user with VF access could cause improper access control for the register interface by sending a malicious command to the firmware. A successful exploit of this vulnerability might lead to denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-33207"
    },
    {
      "rank": 360,
      "cve_id": "CVE-2026-102507",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BishopFox",
      "product": "sliver",
      "cwe": "CWE-125",
      "title": "Sliver 1.7.7 Denial of Service via PE Parser Slice Bounds in Operator RPC",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102507"
    },
    {
      "rank": 361,
      "cve_id": "CVE-2026-102568",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pardus",
      "product": "pardus-parental-control",
      "cwe": "CWE-863",
      "title": "Pardus Parental Control before 0.7.0 Incorrect Authorization via PPCActivator.py",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102568"
    },
    {
      "rank": 362,
      "cve_id": "CVE-2026-102830",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jupyterlab",
      "product": "jupyterlab",
      "cwe": "CWE-79",
      "title": "JupyterLab: Cross-site scripting (XSS) in JupyterLab via crafted language package (jupyterlab.json)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102830"
    },
    {
      "rank": 363,
      "cve_id": "CVE-2026-76729",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Instant ON",
      "cwe": null,
      "title": "Authenticated Format String Vulnerability allows Memory Corruption in HPE Networking Instant ON API Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76729"
    },
    {
      "rank": 364,
      "cve_id": "CVE-2026-66083",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache DolphinScheduler",
      "cwe": "CWE-306",
      "title": "Apache DolphinScheduler: Unauthorized Disclosure of Data Source Information via /datasources/unauth-datasource",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66083"
    },
    {
      "rank": 365,
      "cve_id": "CVE-2026-73597",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway (SCG) Policy Manager",
      "cwe": "CWE-352",
      "title": "Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Cross-Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure, Information tampering, Launch of phishing attacks, and Protection mechanism bypass.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73597"
    },
    {
      "rank": 366,
      "cve_id": "CVE-2026-76730",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Instant ON",
      "cwe": null,
      "title": "Improper PAPI Packet handling leads to unauthorized access in HPE Networking Instant ON APs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76730"
    },
    {
      "rank": 367,
      "cve_id": "CVE-2026-76731",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Instant ON",
      "cwe": null,
      "title": "Authentication Bypass in the Captive Portal of HPE Networking Instant On",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76731"
    },
    {
      "rank": 368,
      "cve_id": "CVE-2026-81862",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow Teradata provider",
      "cwe": "CWE-532",
      "title": "Apache Airflow Teradata provider: Teradata transfer operators embed cloud storage credentials in SQL text, task logs and Teradata query logs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81862"
    },
    {
      "rank": 369,
      "cve_id": "CVE-2026-95327",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Information leak in Networking in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95327"
    },
    {
      "rank": 370,
      "cve_id": "CVE-2026-95328",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-441",
      "title": "Confused deputy in Mobile in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker leveraging social engineering to obtain sensitive information via a co-installed app. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95328"
    },
    {
      "rank": 371,
      "cve_id": "CVE-2026-95336",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Information leak in Transactions Platform in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95336"
    },
    {
      "rank": 372,
      "cve_id": "CVE-2026-95382",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Improper input validation in Auth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95382"
    },
    {
      "rank": 373,
      "cve_id": "CVE-2026-100286",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Devolutions",
      "product": "Server",
      "cwe": "CWE-200",
      "title": "Missing authorization in the data source settings API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated non-administrative user to disclose integration secrets via a crafted API request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100286"
    },
    {
      "rank": 374,
      "cve_id": "CVE-2026-100795",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-770",
      "title": "Denial-of-service in the Networking component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100795"
    },
    {
      "rank": 375,
      "cve_id": "CVE-2026-100812",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-770",
      "title": "Denial-of-service in the Graphics component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100812"
    },
    {
      "rank": 376,
      "cve_id": "CVE-2026-100826",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-770",
      "title": "Denial-of-service in the Storage: StorageManager component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100826"
    },
    {
      "rank": 377,
      "cve_id": "CVE-2026-102623",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift Virtualization 4",
      "cwe": "CWE-476",
      "title": "Kubevirt: kubevirt: virt-controller nil-pointer dereference via malformed ephemeral volume",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102623"
    },
    {
      "rank": 378,
      "cve_id": "CVE-2026-102821",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eugeny",
      "product": "russh",
      "cwe": "CWE-400",
      "title": "Russh: Unbounded memory exhaustion via CHANNEL_OPEN flood during a client-stalled rekey",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102821"
    },
    {
      "rank": 379,
      "cve_id": "CVE-2026-73594",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway (SCG) Policy Manager",
      "cwe": "CWE-295",
      "title": "Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure, Information tampering, and Protection mechanism bypass.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73594"
    },
    {
      "rank": 380,
      "cve_id": "CVE-2026-76732",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Instant ON",
      "cwe": null,
      "title": "Authenticated Local Privilege Escalation Vulnerability in a Daemon of HPE Networking Instant ON",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76732"
    },
    {
      "rank": 381,
      "cve_id": "CVE-2026-76875",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PyPy",
      "product": "PyPy",
      "cwe": "CWE-416",
      "title": "PyPy pyexpat ExternalEntityParserCreate Use-After-Free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76875"
    },
    {
      "rank": 382,
      "cve_id": "CVE-2026-81930",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow Snowflake provider",
      "cwe": "CWE-522",
      "title": "Apache Airflow Snowflake provider: Unvalidated account field redirects SQL API bearer token off-domain",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81930"
    },
    {
      "rank": 383,
      "cve_id": "CVE-2026-86843",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow Teradata provider",
      "cwe": "CWE-89",
      "title": "Apache Airflow Teradata provider: SQL injection via unvalidated Dag Params in the compute-cluster example Dag",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86843"
    },
    {
      "rank": 384,
      "cve_id": "CVE-2026-102598",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pallets",
      "product": "werkzeug",
      "cwe": "CWE-67",
      "title": "Werkzeug safe_join() allows Windows special device names",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102598"
    },
    {
      "rank": 385,
      "cve_id": "CVE-2026-102635",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-908",
      "title": "ImageMagick before 7.1.2-32 and 6.9.13-57 Uninitialized Heap Memory Disclosure in GIF Decoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102635"
    },
    {
      "rank": 386,
      "cve_id": "CVE-2026-102719",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "netxduo",
      "cwe": "CWE-330",
      "title": "Predictable DTLS HelloVerifyRequest Cookie in NetX Secure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102719"
    },
    {
      "rank": 387,
      "cve_id": "CVE-2026-102759",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "NetX Duo",
      "cwe": "CWE-354",
      "title": "NetX Secure TLS accepts an empty application-data record without verifying its message authentication code. In `_nx_secure_verify_mac`, a decrypted application record whose length equals the negotiated MAC size is treated as valid and returns success after advancing the receive sequence number. The received MAC is never generated or compared. Empty TLS application-data records are legal, and are commonly emitted by TLS 1.0 implementations as a BEAST mitigation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102759"
    },
    {
      "rank": 388,
      "cve_id": "CVE-2026-102820",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eugeny",
      "product": "russh",
      "cwe": "CWE-125",
      "title": "pageant: Out-of-bounds read / oversized allocation in `pageant` MemoryMap::read via a malicious Pageant agent (Windows)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102820"
    },
    {
      "rank": 389,
      "cve_id": "CVE-2026-71972",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "u-boot",
      "product": "u-boot",
      "cwe": "CWE-787",
      "title": "U-Boot through 2026.10-rc5 Out-of-Bounds Write in BMP RLE8 Decoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71972"
    },
    {
      "rank": 390,
      "cve_id": "CVE-2026-102723",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "NetX Duo",
      "cwe": "CWE-476",
      "title": "NULL Pointer Dereference on MSRP Attribute Table Exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102723"
    },
    {
      "rank": 391,
      "cve_id": "CVE-2026-102724",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "NetX Duo",
      "cwe": "CWE-476",
      "title": "NULL Pointer Dereference When Evicting the Sole MSRP Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102724"
    },
    {
      "rank": 392,
      "cve_id": "CVE-2026-102725",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "NetX Duo",
      "cwe": "CWE-125",
      "title": "Out-of-bounds Read from Unvalidated MSRP Attribute List Length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102725"
    },
    {
      "rank": 393,
      "cve_id": "CVE-2026-102726",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "NetX Duo",
      "cwe": "CWE-125",
      "title": "Unbounded PPP IPCP Option Parsing Causes a Worker Stall and Out-of-bounds Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102726"
    },
    {
      "rank": 394,
      "cve_id": "CVE-2026-102727",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "NetX Duo",
      "cwe": "CWE-923",
      "title": "FTP Passive Data Connection Not Bound to the Authenticated Control Peer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102727"
    },
    {
      "rank": 395,
      "cve_id": "CVE-2026-102806",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-863",
      "title": "OpenClaw before 2026.9.5 Sandbox Isolation Bypass via Media Pipelines",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102806"
    },
    {
      "rank": 396,
      "cve_id": "CVE-2026-102807",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-863",
      "title": "OpenClaw before 2026.9.4 Authorization Bypass via MCP App Standalone Ticket",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102807"
    },
    {
      "rank": 397,
      "cve_id": "CVE-2026-12345",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Python Software Foundation",
      "product": "CPython",
      "cwe": "CWE-59",
      "title": "Race condition in tempfile.TemporaryDirectory cleanup allows deleting files outside the temporary directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12345"
    },
    {
      "rank": 398,
      "cve_id": "CVE-2026-76114",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway (SCG) Policy Manager",
      "cwe": "CWE-319",
      "title": "Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Cleartext Transmission of Sensitive Information vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76114"
    },
    {
      "rank": 399,
      "cve_id": "CVE-2026-90906",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-79",
      "title": "Joomla! Core - [20260901] - XSS in HTMLHelper::link method in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90906"
    },
    {
      "rank": 400,
      "cve_id": "CVE-2026-90914",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-79",
      "title": "Joomla! Core - [20260904] - Core - XSS in the generic media output layouts in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90914"
    },
    {
      "rank": 401,
      "cve_id": "CVE-2026-92224",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-79",
      "title": "Joomla! Core - [20260911] - Core - XSS in link toolbar layout in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92224"
    },
    {
      "rank": 402,
      "cve_id": "CVE-2026-92225",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-79",
      "title": "Joomla! Core - [20260912] - Core - XSS in module list in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92225"
    },
    {
      "rank": 403,
      "cve_id": "CVE-2026-102729",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "GUIX",
      "cwe": "CWE-131",
      "title": "`gx_binres_theme_load()` sizes its theme buffer for the theme it was asked for, and allocates it even when the resource holds no theme with that id. A theme id at or past the theme count declared by the resource gets a buffer of zero bytes. The load pass then walks past the end of the theme table, takes whatever follows as a theme header, and writes a `GX_THEME` and its tables into that zero-byte buffer.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102729"
    },
    {
      "rank": 404,
      "cve_id": "CVE-2026-102938",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pypa",
      "product": "virtualenv",
      "cwe": "CWE-93",
      "title": "virtualenv writes prompt values into pyvenv.cfg without sanitizing line boundaries, allowing configuration injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102938"
    },
    {
      "rank": 405,
      "cve_id": "CVE-2026-102371",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canonical",
      "product": "Ubuntu Pro for WSL",
      "cwe": "CWE-214",
      "title": "wsl-pro-service: Ubuntu Pro token exposed via process command-line arguments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102371"
    },
    {
      "rank": 406,
      "cve_id": "CVE-2026-102711",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "`eclipse-threadx/threadx` (module manager / loadable-module loader)",
      "cwe": "CWE-125",
      "title": "Two issues in the ThreadX loadable-module loader, reached when a device loads an attacker-controlled module object via `_txm_module_manager_memory_load` / `_txm_module_manager_in_place_load` — APIs that take ONLY a base pointer, no image length, so every size/offset field in `TXM_MODULE_PREAMBLE` is fully attacker-trusted: (1) a heap OOB **read** (`code_size` trusted as the source-image length in the code-copy loop), and (2) a control-flow-integrity / defense-in-depth gap (module entry/start/callback/stop pointers computed as `code_start + preamble_offset` with only a `!= 0` check, and the preamble `checksum` never verified). No controlled OOB write was found (honest — the copy destination is overflow-guarded).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102711"
    },
    {
      "rank": 407,
      "cve_id": "CVE-2026-102491",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mahonelau",
      "product": "kykms",
      "cwe": "CWE-74",
      "title": "mahonelau kykms SqlInjectionUtil QueryGenerator.java QueryGenerator.doMultiFieldsOrder sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102491"
    },
    {
      "rank": 408,
      "cve_id": "CVE-2026-102616",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "risesoft-y9",
      "product": "WorkFlow-Engine",
      "cwe": "CWE-74",
      "title": "risesoft-y9 WorkFlow-Engine OAuth2 Resource Filter CustomHistoricProcessServiceImpl.java getByIdAndYear sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102616"
    },
    {
      "rank": 409,
      "cve_id": "CVE-2026-73599",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway (SCG) Policy Manager",
      "cwe": "CWE-601",
      "title": "Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73599"
    },
    {
      "rank": 410,
      "cve_id": "CVE-2026-95279",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "UI misrepresentation in Omnibox in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95279"
    },
    {
      "rank": 411,
      "cve_id": "CVE-2026-95288",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "UI misrepresentation in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95288"
    },
    {
      "rank": 412,
      "cve_id": "CVE-2026-95291",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "UI misrepresentation in SecurityIndicators in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95291"
    },
    {
      "rank": 413,
      "cve_id": "CVE-2026-95294",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "UI misrepresentation in Browser in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95294"
    },
    {
      "rank": 414,
      "cve_id": "CVE-2026-95307",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "UI misrepresentation in ExtensionsMenu in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95307"
    },
    {
      "rank": 415,
      "cve_id": "CVE-2026-95309",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "UI misrepresentation in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95309"
    },
    {
      "rank": 416,
      "cve_id": "CVE-2026-95320",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in Navigation in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95320"
    },
    {
      "rank": 417,
      "cve_id": "CVE-2026-95321",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "UI misrepresentation in Payments in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95321"
    },
    {
      "rank": 418,
      "cve_id": "CVE-2026-95323",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "UI misrepresentation in Chromium in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95323"
    },
    {
      "rank": 419,
      "cve_id": "CVE-2026-95337",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "UI misrepresentation in Messages in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95337"
    },
    {
      "rank": 420,
      "cve_id": "CVE-2026-95363",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "UI misrepresentation in FileSystem in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95363"
    },
    {
      "rank": 421,
      "cve_id": "CVE-2026-95364",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Improper input validation in Passwords in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95364"
    },
    {
      "rank": 422,
      "cve_id": "CVE-2026-95371",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in Views in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95371"
    },
    {
      "rank": 423,
      "cve_id": "CVE-2026-100287",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Devolutions",
      "product": "Server",
      "cwe": "CWE-862",
      "title": "Missing authorization in the attachment history API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated low-privileged user to permanently delete or restore vault attachments via a crafted API request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100287"
    },
    {
      "rank": 424,
      "cve_id": "CVE-2026-102305",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "UI misrepresentation in SignIn in Google Chrome on on iOS prior to 154.0.8037.92 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102305"
    },
    {
      "rank": 425,
      "cve_id": "CVE-2026-102314",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "UI misrepresentation in TabStrip in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102314"
    },
    {
      "rank": 426,
      "cve_id": "CVE-2026-102904",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jupyterlab",
      "product": "jupyterlab",
      "cwe": "CWE-88",
      "title": "JupyterLab: Argument injection in JupyterLab extension uninstall exposes server-readable files and internal URLs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102904"
    },
    {
      "rank": 427,
      "cve_id": "CVE-2026-53989",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Finsys",
      "product": "dockhand",
      "cwe": "CWE-601",
      "title": "Dockhand < 1.0.36 Open Redirect via OIDC Initiation Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53989"
    },
    {
      "rank": 428,
      "cve_id": "CVE-2026-75804",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSSL",
      "product": "OpenSSL",
      "cwe": "CWE-770",
      "title": "QUIC Connection-Level Flow Control is Not Enforced for Streams",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75804"
    },
    {
      "rank": 429,
      "cve_id": "CVE-2026-75805",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSSL",
      "product": "OpenSSL",
      "cwe": "CWE-476",
      "title": "NULL Pointer Dereference in CMP Client Revocation Response Handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75805"
    },
    {
      "rank": 430,
      "cve_id": "CVE-2026-75806",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSSL",
      "product": "OpenSSL",
      "cwe": "CWE-1284",
      "title": "Unauthenticated and Undersized DTLS 1.2 AEAD Record Causes DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75806"
    },
    {
      "rank": 431,
      "cve_id": "CVE-2026-78214",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache DolphinScheduler",
      "cwe": "CWE-863",
      "title": "Apache DolphinScheduler: Actuator Endpoint Authentication Bypass via Percent-Encoded Paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78214"
    },
    {
      "rank": 432,
      "cve_id": "CVE-2026-81841",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Grafana",
      "product": "Grafana Enterprise",
      "cwe": "CWE-862",
      "title": "Paused shared dashboard access tokens still expose data source configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81841"
    },
    {
      "rank": 433,
      "cve_id": "CVE-2026-86105",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Fireware OS",
      "cwe": "CWE-176",
      "title": "Fireware OS Improper Authorization in Access Portal Reverse Proxy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86105"
    },
    {
      "rank": 434,
      "cve_id": "CVE-2026-95360",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-367",
      "title": "Race condition in Editing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95360"
    },
    {
      "rank": 435,
      "cve_id": "CVE-2026-95367",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Information leak in DataTransfer in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95367"
    },
    {
      "rank": 436,
      "cve_id": "CVE-2026-95384",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-362",
      "title": "Race condition in Transactions Platform in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95384"
    },
    {
      "rank": 437,
      "cve_id": "CVE-2026-100295",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Anjvision",
      "product": "YSSD-RTMP-H5",
      "cwe": "CWE-489",
      "title": "Active debug code in Anjvision YSSD-RTMP-H5",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100295"
    },
    {
      "rank": 438,
      "cve_id": "CVE-2026-102720",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "eclipse-threadx/netxduo",
      "cwe": "CWE-125",
      "title": "A DHCP server, or anyone on the LAN who answers a DISCOVER first, can make the client read about a kilobyte past the end of the received message. The option walk keeps a pointer and an offset in step, and the only bound check uses the offset: ```c /* addons/dhcp/nxd_dhcp_client.c:7538, 7572 */ while (i < length - 1) { ... size = *(++data); /* data moves 1: type -> length byte */ data += size + 1; /* data moves size + 1 more */ i += size + 1; /* i moves only size + 1 */ } ``` A TLV option occupies size + 2 bytes. `data` is advanced by size + 2 in total, `i` by size + 1, so the offset falls one byte behind the real read position for every option the walk skips. After enough skipped options the check `i < length - 1` still holds while `data` is already past the end of the message, and the subsequent read of the type and length bytes comes from whatever follows. A single OFFER carrying a long run of skippable options is enough: ``` ERROR: AddressSanitizer: heap-buffer-overflow READ of size 1 at 0x61b000000794 thread T5 #0 _nx_dhcp_search_buffer addons/dhcp/nxd_dhcp_client.c:7541 #1 _nx_dhcp_get_option_value addons/dhcp/nxd_dhcp_client.c:7082 0x61b000000794 is located 164 bytes to the right of 1648-byte region ``` A well formed OFFER through the same path is handled normally, the client records the offer and moves to REQUESTING, so the difference is the option layout rather than the harness. The read runs in the DHCP client thread while the client is still unconfigured, so it happens on every boot in reach of a hostile DHCP responder. The values read are used to configure the interface, which is how the disclosed bytes become observable. Advance `i` by size + 2, or derive the bound from `data` rather than keeping a second counter.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102720"
    },
    {
      "rank": 439,
      "cve_id": "CVE-2026-102879",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "claraverse-space",
      "product": "ClaraVerse",
      "cwe": "CWE-918",
      "title": "ClaraVerse through 0.3.1 SSRF Protection Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102879"
    },
    {
      "rank": 440,
      "cve_id": "CVE-2026-71973",
      "cvss_base": 5.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "u-boot",
      "product": "u-boot",
      "cwe": "CWE-190",
      "title": "U-Boot before 2026.10-rc4 Integer Overflow in SquashFS Directory Table Allocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71973"
    },
    {
      "rank": 441,
      "cve_id": "CVE-2026-22101",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EVbee",
      "product": "DC-80",
      "cwe": "CWE-200",
      "title": "Sensitive information leak through hidden menu",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22101"
    },
    {
      "rank": 442,
      "cve_id": "CVE-2026-49243",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "webmin",
      "product": "webmin",
      "cwe": "CWE-79",
      "title": "Webmin: Reflected XSS in the Configuration module",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49243"
    },
    {
      "rank": 443,
      "cve_id": "CVE-2026-90916",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-284",
      "title": "Joomla! Core - [20260906] - Core - Improper ACL checks in content history comparison view in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90916"
    },
    {
      "rank": 444,
      "cve_id": "CVE-2026-92223",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-284",
      "title": "Joomla! Core - [20260910] - Core - Improper ACL checks for workflow stage changes in Joomla 5.0.0-5.4.8, 6.0.0-6.1.3",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92223"
    },
    {
      "rank": 445,
      "cve_id": "CVE-2026-100289",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Devolutions",
      "product": "Server",
      "cwe": "CWE-862",
      "title": "Missing authorization in the gateway network scan token API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated low-privileged user to generate a network scan token and perform internal network discovery and port scanning through the gateway via a crafted API request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100289"
    },
    {
      "rank": 446,
      "cve_id": "CVE-2026-76733",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Instant ON",
      "cwe": null,
      "title": "Authenticated Denial-of-Service Vulnerability in HPE Networking Instant On API Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76733"
    },
    {
      "rank": 447,
      "cve_id": "CVE-2026-71189",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Toptech Systems",
      "product": "TMS7",
      "cwe": "CWE-79",
      "title": "Toptech TMS7 and TopHAT Cross-site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71189"
    },
    {
      "rank": 448,
      "cve_id": "CVE-2026-76734",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Instant ON",
      "cwe": null,
      "title": "Unauthenticated Memory Corruption Vulnerability leads to Denial-of-Service in HPE Networking Instant On",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76734"
    },
    {
      "rank": 449,
      "cve_id": "CVE-2026-95305",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "UI misrepresentation in Chromoting in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI elements via crafted network traffic. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95305"
    },
    {
      "rank": 450,
      "cve_id": "CVE-2026-95346",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "UI misrepresentation in Chromoting in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via crafted network traffic. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95346"
    },
    {
      "rank": 451,
      "cve_id": "CVE-2026-73595",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway (SCG) Policy Manager",
      "cwe": "CWE-494",
      "title": "Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains a Download of Code Without Integrity Check vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Code execution, Information disclosure, Information tampering, and Protection mechanism bypass.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73595"
    },
    {
      "rank": 452,
      "cve_id": "CVE-2026-95293",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-908",
      "title": "Uninitialized resource in GPU in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95293"
    },
    {
      "rank": 453,
      "cve_id": "CVE-2026-95332",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Use of uninitialized variable in Tint in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95332"
    },
    {
      "rank": 454,
      "cve_id": "CVE-2026-102307",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-908",
      "title": "Uninitialized resource in Dawn in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102307"
    },
    {
      "rank": 455,
      "cve_id": "CVE-2026-102313",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-908",
      "title": "Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 154.0.8037.92 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102313"
    },
    {
      "rank": 456,
      "cve_id": "CVE-2026-102318",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in WebGL in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102318"
    },
    {
      "rank": 457,
      "cve_id": "CVE-2026-95295",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Information leak in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 allowed a local attacker to leak sensitive information via physical access. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95295"
    },
    {
      "rank": 458,
      "cve_id": "CVE-2026-71897",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache DolphinScheduler",
      "cwe": "CWE-863",
      "title": "Apache DolphinScheduler: Allows unauthorized workflow operations through batch-copy and batch-move endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71897"
    },
    {
      "rank": 459,
      "cve_id": "CVE-2026-71898",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache DolphinScheduler",
      "cwe": "CWE-863",
      "title": "Apache DolphinScheduler: Improper Authorization Allows Project Read-Only Users to Execute Workflows and Tamper with Workflow Definitions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71898"
    },
    {
      "rank": 460,
      "cve_id": "CVE-2026-71974",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "u-boot",
      "product": "u-boot",
      "cwe": "CWE-787",
      "title": "U-Boot before 2026.10-rc3 Out-of-Bounds Write via Android Bootmeth Partition Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71974"
    },
    {
      "rank": 461,
      "cve_id": "CVE-2026-76720",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise",
      "product": "HPE OneView",
      "cwe": "CWE-601",
      "title": "HPE OneView - URL Redirect vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76720"
    },
    {
      "rank": 462,
      "cve_id": "CVE-2026-79348",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "KitchenAsty through 0.3.0 contains a broken object level authorization (IDOR) vulnerability in the reservations API. The endpoint GET /api/reservations/:id in packages/server applies the authenticate middleware but performs no ownership or role check, and the getReservation handler in packages/server/src/controllers/reservation.controller.ts returns the record retrieved by the client-supplied identifier without comparing reservation.customerId to the authenticated principal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79348"
    },
    {
      "rank": 463,
      "cve_id": "CVE-2026-81569",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache DolphinScheduler",
      "cwe": "CWE-285",
      "title": "Apache DolphinScheduler: Improper Authorization in Sub-Workflow Tasks Allows Unauthorized Workflow Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81569"
    },
    {
      "rank": 464,
      "cve_id": "CVE-2026-81842",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Grafana",
      "product": "Grafana Enterprise",
      "cwe": "CWE-863",
      "title": "Library panel can be moved into a folder without library panel create permission",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81842"
    },
    {
      "rank": 465,
      "cve_id": "CVE-2026-93330",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Devolutions",
      "product": "Server",
      "cwe": "CWE-696",
      "title": "Improper rule enforcement in the PAM Active Directory provider in Devolutions Server 2026.3.5 allows a user with PAM edit permissions to bypass the Devolutions Gateway host ruleset.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93330"
    },
    {
      "rank": 466,
      "cve_id": "CVE-2026-95289",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in Scroll in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95289"
    },
    {
      "rank": 467,
      "cve_id": "CVE-2026-95296",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in Core in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95296"
    },
    {
      "rank": 468,
      "cve_id": "CVE-2026-95368",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95368"
    },
    {
      "rank": 469,
      "cve_id": "CVE-2026-96869",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-200",
      "title": "Information disclosure in the Networking component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96869"
    },
    {
      "rank": 470,
      "cve_id": "CVE-2026-100766",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-200",
      "title": "Information disclosure in the Networking: JAR component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100766"
    },
    {
      "rank": 471,
      "cve_id": "CVE-2026-100783",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-457",
      "title": "Uninitialized memory in the Audio/Video component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100783"
    },
    {
      "rank": 472,
      "cve_id": "CVE-2026-100799",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-457",
      "title": "Uninitialized memory in the Graphics: WebGPU component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100799"
    },
    {
      "rank": 473,
      "cve_id": "CVE-2026-100802",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-457",
      "title": "Uninitialized memory in the Graphics: WebGPU component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100802"
    },
    {
      "rank": 474,
      "cve_id": "CVE-2026-100806",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-457",
      "title": "Uninitialized memory in the Graphics: WebGPU component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100806"
    },
    {
      "rank": 475,
      "cve_id": "CVE-2026-102300",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-908",
      "title": "Uninitialized resource in WebGPU in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102300"
    },
    {
      "rank": 476,
      "cve_id": "CVE-2026-102303",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-908",
      "title": "Uninitialized resource in GPU in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102303"
    },
    {
      "rank": 477,
      "cve_id": "CVE-2026-102325",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-908",
      "title": "Uninitialized resource in Skia in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102325"
    },
    {
      "rank": 478,
      "cve_id": "CVE-2026-102824",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eugeny",
      "product": "russh",
      "cwe": "CWE-327",
      "title": "Russh: Missing X25519 zero-point validation in hybrid ML-KEM key exchange",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102824"
    },
    {
      "rank": 479,
      "cve_id": "CVE-2026-76735",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Instant ON",
      "cwe": null,
      "title": "Authenticated Local Sensitive Information Disclosure in HPE Networking Instant On",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76735"
    },
    {
      "rank": 480,
      "cve_id": "CVE-2026-73596",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway (SCG) Policy Manager",
      "cwe": "CWE-1188",
      "title": "Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Initialization of a Resource with an Insecure Default vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges, Information tampering, Protection mechanism bypass, and Unauthorized access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73596"
    },
    {
      "rank": 481,
      "cve_id": "CVE-2026-54872",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSSL",
      "product": "OpenSSL",
      "cwe": "CWE-208",
      "title": "Timing Side-Channel in Scalar Multiplication for Non-NIST EC Curves",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54872"
    },
    {
      "rank": 482,
      "cve_id": "CVE-2026-54875",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSSL",
      "product": "OpenSSL",
      "cwe": "CWE-208",
      "title": "Non-Constant-Time SM2 Scalar Multiplication on ARM64 and RISC-V",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54875"
    },
    {
      "rank": 483,
      "cve_id": "CVE-2026-77696",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSSL",
      "product": "OpenSSL",
      "cwe": "CWE-208",
      "title": "Timing Side-Channel in SM2 Signature Generation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77696"
    },
    {
      "rank": 484,
      "cve_id": "CVE-2026-102822",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eugeny",
      "product": "russh",
      "cwe": "CWE-129",
      "title": "russh: negotiating a MAC-requiring block cipher (CTR/CBC) with mac=none causes a slice-index-out-of-range panic",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102822"
    },
    {
      "rank": 485,
      "cve_id": "CVE-2026-102825",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eugeny",
      "product": "russh",
      "cwe": "CWE-307",
      "title": "Russh: Configured server auth-attempt cap is not enforced in the USERAUTH_REQUEST runtime path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102825"
    },
    {
      "rank": 486,
      "cve_id": "CVE-2026-102601",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thephpleague",
      "product": "flysystem",
      "cwe": "CWE-150",
      "title": "Flysystem: WhitespacePathNormalizer's control-character (CorruptedPathDetected) check is bypassed by malformed UTF-8 in the path, affecting every adapter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102601"
    },
    {
      "rank": 487,
      "cve_id": "CVE-2026-95308",
      "cvss_base": 3.4,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-190",
      "title": "Integer overflow in Metrics in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95308"
    },
    {
      "rank": 488,
      "cve_id": "CVE-2026-95324",
      "cvss_base": 3.4,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-908",
      "title": "Uninitialized resource in GPU in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95324"
    },
    {
      "rank": 489,
      "cve_id": "CVE-2026-95359",
      "cvss_base": 3.4,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-908",
      "title": "Uninitialized resource in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95359"
    },
    {
      "rank": 490,
      "cve_id": "CVE-2026-102311",
      "cvss_base": 3.4,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-908",
      "title": "Uninitialized resource in GPU in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102311"
    },
    {
      "rank": 491,
      "cve_id": "CVE-2026-102315",
      "cvss_base": 3.4,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-908",
      "title": "Uninitialized resource in Media in Google Chrome on on Windows prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102315"
    },
    {
      "rank": 492,
      "cve_id": "CVE-2026-102319",
      "cvss_base": 3.4,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-908",
      "title": "Uninitialized resource in GPU in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102319"
    },
    {
      "rank": 493,
      "cve_id": "CVE-2026-76736",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Instant ON",
      "cwe": null,
      "title": "Authenticated Local Buffer Overflow Vulnerability leads to Denial-of-Service in HPE Networking Instant On",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76736"
    },
    {
      "rank": 494,
      "cve_id": "CVE-2026-95312",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Information leak in Passwords in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95312"
    },
    {
      "rank": 495,
      "cve_id": "CVE-2026-95317",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in MediaCapture in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted Chrome extension. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95317"
    },
    {
      "rank": 496,
      "cve_id": "CVE-2026-73593",
      "cvss_base": 3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway (SCG) Policy Manager",
      "cwe": "CWE-489",
      "title": "Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Active Debug Code vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure, Information tampering, Protection mechanism bypass, and Unauthorized access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73593"
    },
    {
      "rank": 497,
      "cve_id": "CVE-2026-76737",
      "cvss_base": 3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Instant ON",
      "cwe": null,
      "title": "Authenticated Local Path Traversal Vulnerability Leads to Denial-of-Service in HPE Networking Instant On",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76737"
    },
    {
      "rank": 498,
      "cve_id": "CVE-2026-95302",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in WebAPKs in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker to obtain cross-origin data via a co-installed app. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95302"
    },
    {
      "rank": 499,
      "cve_id": "CVE-2026-95316",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-252",
      "title": "Unchecked return value in Performance in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially read memory via a local program. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95316"
    },
    {
      "rank": 500,
      "cve_id": "CVE-2026-76738",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Instant ON",
      "cwe": null,
      "title": "Authenticated Buffer Overflow Vulnerability in the API Endpoint of HPE Networking Instant On Causes Denial-of-Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76738"
    },
    {
      "rank": 501,
      "cve_id": "CVE-2026-101267",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pretix",
      "product": "pretix",
      "cwe": "CWE-862",
      "title": "Revenue information leak",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101267"
    },
    {
      "rank": 502,
      "cve_id": "CVE-2026-97711",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yahoo",
      "product": "serialize-javascript",
      "cwe": "CWE-79",
      "title": "Serialize JavaScript: Cross-site scripting (XSS) via unescaped </script> in serialized function bodies",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97711"
    },
    {
      "rank": 503,
      "cve_id": "CVE-2026-101269",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pretix",
      "product": "pretix",
      "cwe": "CWE-287",
      "title": "Incorrect session validation for API-uploaded files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101269"
    },
    {
      "rank": 504,
      "cve_id": "CVE-2026-102630",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "unopim",
      "product": "unopim",
      "cwe": "CWE-348",
      "title": "UnoPim 2.0.0 before 2.0.1 and 2.1.0 before 2.1.1 Cache Poisoning via X-Forwarded-Host",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102630"
    },
    {
      "rank": 505,
      "cve_id": "CVE-2026-69662",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Toptech Systems",
      "product": "TMS7",
      "cwe": "CWE-95",
      "title": "Toptech TMS7 and TopHAT Eval Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69662"
    },
    {
      "rank": 506,
      "cve_id": "CVE-2026-101270",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pretix",
      "product": "pretix",
      "cwe": "CWE-79",
      "title": "HTML injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101270"
    },
    {
      "rank": 507,
      "cve_id": "CVE-2026-101271",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pretix",
      "product": "pretix",
      "cwe": "CWE-613",
      "title": "OAuth credentials not disabled when application is disabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101271"
    },
    {
      "rank": 508,
      "cve_id": "CVE-2026-102877",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getfider",
      "product": "fider",
      "cwe": "CWE-918",
      "title": "Fider before 0.38.0 SSRF via DNS rebinding in webhook validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102877"
    },
    {
      "rank": 509,
      "cve_id": "CVE-2026-102771",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Naichen",
      "product": "ThinkCMF",
      "cwe": "CWE-791",
      "title": "Naichen ThinkCMF Email Template MailController.php templatePut special elements in template engine",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102771"
    },
    {
      "rank": 510,
      "cve_id": "CVE-2026-102620",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Freedesktop",
      "product": "Poppler",
      "cwe": "CWE-189",
      "title": "Freedesktop Poppler FoFiTrueType.cc cvtSfnts integer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102620"
    },
    {
      "rank": 511,
      "cve_id": "CVE-2026-102621",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Freedesktop",
      "product": "Poppler",
      "cwe": "CWE-189",
      "title": "Freedesktop Poppler SplashClip.cc clipToPath integer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102621"
    },
    {
      "rank": 512,
      "cve_id": "CVE-2026-101268",
      "cvss_base": 1.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pretix",
      "product": "pretix",
      "cwe": "CWE-384",
      "title": "Customer session fixation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101268"
    },
    {
      "rank": 513,
      "cve_id": "CVE-2026-101266",
      "cvss_base": 1.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pretix",
      "product": "pretix",
      "cwe": "CWE-20",
      "title": "Checkout validation bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101266"
    },
    {
      "rank": 514,
      "cve_id": "CVE-2024-31026",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in Greek Universities Network (GUnet) Open eClass Platform v.3.15 allows a remote attacker to execute arbitrary code via the chat input field in the course module.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-31026"
    },
    {
      "rank": 515,
      "cve_id": "CVE-2024-31027",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Cross Site Scripting vulnerability in Greek Universities Network (GUnet) Open eClass Platform v.3.15 allows a remote attacker to execute arbitrary code via the last name, first name, and username parameters in the user registration functionality.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-31027"
    },
    {
      "rank": 516,
      "cve_id": "CVE-2026-35189",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSSL",
      "product": "OpenSSL",
      "cwe": "CWE-770",
      "title": "Excessive Memory Allocation in Relative CRLDP Processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35189"
    },
    {
      "rank": 517,
      "cve_id": "CVE-2026-35191",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSSL",
      "product": "OpenSSL",
      "cwe": "CWE-440",
      "title": "QUIC Unvalidated Amplification Credit may be Over Accounted",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35191"
    },
    {
      "rank": 518,
      "cve_id": "CVE-2026-42772",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSSL",
      "product": "OpenSSL",
      "cwe": "CWE-407",
      "title": "Potential CPU DoS via O(n^2) Fragment Reassembly in QUIC",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42772"
    },
    {
      "rank": 519,
      "cve_id": "CVE-2026-54873",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSSL",
      "product": "OpenSSL",
      "cwe": "CWE-770",
      "title": "QUIC STREAM Fragment Metadata DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54873"
    },
    {
      "rank": 520,
      "cve_id": "CVE-2026-67987",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains polynomial-time regular expression denial-of-service conditions in think-tag response parsing on Ruby 3.1.x. A malicious or anomalous model response containing many unterminated <think> tags can cause excessive CPU consumption in two consecutive regular expressions and delay chat-completion processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67987"
    },
    {
      "rank": 521,
      "cve_id": "CVE-2026-67993",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f contains a login cross-site request forgery issue in the static credentials callback.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67993"
    },
    {
      "rank": 522,
      "cve_id": "CVE-2026-71899",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache DolphinScheduler",
      "cwe": "CWE-863",
      "title": "Apache DolphinScheduler: Missing Authorization in query-dynamic-sub-workflows API Leads to Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71899"
    },
    {
      "rank": 523,
      "cve_id": "CVE-2026-79403",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in Kilo Code before v7.4.1 allows a local attacker to execute arbitrary code via the permission/allow-everything endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79403"
    },
    {
      "rank": 524,
      "cve_id": "CVE-2026-79417",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Improper Access Control in ArgusMonitor.sys in Argotronic eGbR ArgusMonitor 7.4.02 and earlier allows local, low-privileged users to bypass device handle access restrictions via a TOCTOU condition in IRP_MJ_CREATE and send a crafted IOCTL 0x9C4024A8 request, causing denial-of-service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79417"
    },
    {
      "rank": 525,
      "cve_id": "CVE-2026-79534",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "mark3labs mcp-filesystem-server v0.11.1 is vulnerable to Directory Traversal due to an improper link resolution in validatePath (filesystemserver/handler/helper.go). When filepath.EvalSymlinks returns os.IsNotExist for a dangling symlink, the fallback validates only the parent directory and returns the unresolved path, so write_file (and modify_file, copy_file, move_file, create_directory) follows a pre-existing dangling symlink located inside an allowed directory and creates a file outside the configured allowed directories.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79534"
    },
    {
      "rank": 526,
      "cve_id": "CVE-2026-79535",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "mbailey VoiceMode <= 8.10.1 is vulnerable to OS Command Injection. The update_config MCP tool (and the \"voicemode config set\" CLI) writes a caller-supplied value into ~/.voicemode/voicemode.env without shell-safe escaping.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79535"
    },
    {
      "rank": 527,
      "cve_id": "CVE-2026-79536",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "bytebase dbhub v1.2.0 was discovered to contain a SQL injection vulnerability in the /utils/sql-parser.ts component. This vulnerability allows attackers to access sensitive databse information via a crafted SQL statement.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79536"
    },
    {
      "rank": 528,
      "cve_id": "CVE-2026-79537",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "metatool-ai MetaMCP through 2.4.22 contains an insecure direct object reference (IDOR) in the MCP transport session dispatch. The session store (getSession in session-lifetime-manager.ts) is keyed only by the client-supplied mcp-session-id header with no owner, namespace, or endpoint binding, and the per-endpoint authorization middleware validates only the URL endpoint's owner, never the session. An attacker who supplies another tenant's session id \" obtained without authentication from GET /metamcp/health/sessions, which discloses active session IDs and namespace UUIDs \" can list and execute the victim tenant's private MCP tools and exfiltrate their data using the victim's forwarded credentials.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79537"
    },
    {
      "rank": 529,
      "cve_id": "CVE-2026-93332",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Devolutions",
      "product": "Server",
      "cwe": "CWE-862",
      "title": "Improper access control in the partial connection API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated low-privileged user to read, create, modify, and delete System Vault entries via a crafted API request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93332"
    },
    {
      "rank": 530,
      "cve_id": "CVE-2026-94952",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "A stack-based buffer overflow vulnerability exists in the web management interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030. It is reachable through the route /boafrm/formPortFw (port-forwarding configuration handler) and is triggered by the ip_subnet and fw_ip request parameters during the rule-addition flow.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94952"
    },
    {
      "rank": 531,
      "cve_id": "CVE-2026-94953",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "A stack-based buffer overflow vulnerability exists in the web management interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030. It is reachable through the route /boafrm/formAjaxSet using the topicurl=setting/setWiFiRepeaterConfig branch and the ApCliWEPKey field.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94953"
    },
    {
      "rank": 532,
      "cve_id": "CVE-2026-94954",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "A stack-based buffer overflow vulnerability exists in the web management interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030. It is reachable through the route /boafrm/formFilter (access-control / URL filter configuration handler) and is triggered by the url request parameter when the addFilterUrl (or addFilterUrlFlag) action flag is set.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94954"
    },
    {
      "rank": 533,
      "cve_id": "CVE-2026-95275",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-706",
      "title": "Incorrect reference resolution in MediaStream in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95275"
    },
    {
      "rank": 534,
      "cve_id": "CVE-2026-95278",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in WakeLock in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95278"
    },
    {
      "rank": 535,
      "cve_id": "CVE-2026-95284",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-122",
      "title": "Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95284"
    },
    {
      "rank": 536,
      "cve_id": "CVE-2026-95285",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in WebView in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95285"
    },
    {
      "rank": 537,
      "cve_id": "CVE-2026-95287",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in Navigation in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95287"
    },
    {
      "rank": 538,
      "cve_id": "CVE-2026-95290",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in NFC in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95290"
    },
    {
      "rank": 539,
      "cve_id": "CVE-2026-95292",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in Safebrowsing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95292"
    },
    {
      "rank": 540,
      "cve_id": "CVE-2026-95297",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in Contextual Tasks in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95297"
    },
    {
      "rank": 541,
      "cve_id": "CVE-2026-95300",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95300"
    },
    {
      "rank": 542,
      "cve_id": "CVE-2026-95301",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in Extensions in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95301"
    },
    {
      "rank": 543,
      "cve_id": "CVE-2026-95303",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-459",
      "title": "Incomplete cleanup in SmartCard in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95303"
    },
    {
      "rank": 544,
      "cve_id": "CVE-2026-95314",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in HID in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95314"
    },
    {
      "rank": 545,
      "cve_id": "CVE-2026-95326",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-459",
      "title": "Incomplete cleanup in Bluetooth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95326"
    },
    {
      "rank": 546,
      "cve_id": "CVE-2026-95330",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-754",
      "title": "Improper state validation in Downloads in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95330"
    },
    {
      "rank": 547,
      "cve_id": "CVE-2026-95340",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in PictureInPicture in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95340"
    },
    {
      "rank": 548,
      "cve_id": "CVE-2026-95342",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95342"
    },
    {
      "rank": 549,
      "cve_id": "CVE-2026-95344",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-367",
      "title": "Race condition in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass site isolation via a crafted Chrome extension. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95344"
    },
    {
      "rank": 550,
      "cve_id": "CVE-2026-95352",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95352"
    },
    {
      "rank": 551,
      "cve_id": "CVE-2026-95358",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in Mobile in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker to bypass system access restrictions into a privileged page via a co-installed app. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95358"
    },
    {
      "rank": 552,
      "cve_id": "CVE-2026-95361",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-441",
      "title": "Confused deputy in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95361"
    },
    {
      "rank": 553,
      "cve_id": "CVE-2026-95362",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-352",
      "title": "Cross-site request forgery in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95362"
    },
    {
      "rank": 554,
      "cve_id": "CVE-2026-95366",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-672",
      "title": "Use of released resource in Core in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95366"
    },
    {
      "rank": 555,
      "cve_id": "CVE-2026-95370",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-841",
      "title": "Inappropriate implementation in NFC in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95370"
    },
    {
      "rank": 556,
      "cve_id": "CVE-2026-95374",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in Network in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95374"
    },
    {
      "rank": 557,
      "cve_id": "CVE-2026-95375",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in BrowserTag in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95375"
    },
    {
      "rank": 558,
      "cve_id": "CVE-2026-95376",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-610",
      "title": "Externally controlled reference in DevTools in Google Chrome prior to 154.0.8037.57 allowed an adjacent attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95376"
    },
    {
      "rank": 559,
      "cve_id": "CVE-2026-95385",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-841",
      "title": "Inappropriate implementation in PlatformIntegration in Google Chrome on on Windows prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95385"
    },
    {
      "rank": 560,
      "cve_id": "CVE-2026-97395",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Polaris",
      "cwe": null,
      "title": "Apache Polaris: Allows authorized table writers to redirect server-side Iceberg FileIO requests to attacker-controlled endpoints using operation-scoped storage credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97395"
    },
    {
      "rank": 561,
      "cve_id": "CVE-2026-98164",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: x86/mmu: Check write tracking in all address spaces",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98164"
    },
    {
      "rank": 562,
      "cve_id": "CVE-2026-100238",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wikimedia Foundation",
      "product": "Mediawiki - Flow Extension",
      "cwe": "CWE-79",
      "title": "Flow colon-separator and flow-guidedtour-optin-welcome-description messages allow stored XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100238"
    },
    {
      "rank": 563,
      "cve_id": "CVE-2026-100240",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wikimedia Foundation",
      "product": "Mediawiki - TemplateSandbox Extension",
      "cwe": "CWE-862",
      "title": "TemplateSandbox does not check read permissions for the page being previewed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100240"
    },
    {
      "rank": 564,
      "cve_id": "CVE-2026-100241",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wikimedia Foundation",
      "product": "Mediawiki - EventBus Extension",
      "cwe": "CWE-200",
      "title": "Private change tags exposed to anonymous users via revision-tags-change events",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100241"
    },
    {
      "rank": 565,
      "cve_id": "CVE-2026-100242",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wikimedia Foundation",
      "product": "Mediawiki - DataTransfer Extension",
      "cwe": "CWE-400",
      "title": "DataTransfer depends on phpspreadsheet version vulnerable to CVE-2026-59933 (XLS/OLE memory exhaustion)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100242"
    },
    {
      "rank": 566,
      "cve_id": "CVE-2026-100243",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wikimedia Foundation",
      "product": "Mediawiki - WikiSEO Extension",
      "cwe": "CWE-79",
      "title": "Stored XSS in WikiSEO author and image properties on action=info",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100243"
    },
    {
      "rank": 567,
      "cve_id": "CVE-2026-100244",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wikimedia Foundation",
      "product": "Mediawiki - CentralAuth Extension",
      "cwe": "CWE-200",
      "title": "CentralAuth exposes locally suppressed block information via globaluserinfo API and Special:CentralAuth (incomplete fix for CVE-2025-62669)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100244"
    },
    {
      "rank": 568,
      "cve_id": "CVE-2026-100245",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wikimedia Foundation",
      "product": "Mediawiki - Wikibase Extension",
      "cwe": "CWE-79",
      "title": "Stored XSS on Wikibase Special:SetSiteLink via unescaped system message",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100245"
    },
    {
      "rank": 569,
      "cve_id": "CVE-2026-100288",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Devolutions",
      "product": "Server",
      "cwe": "CWE-312",
      "title": "Cleartext storage of sensitive information in the database in Devolutions Server 2026.3.5.0 and earlier allows an attacker with read access to the database to obtain external identity provider tokens and active session identifiers via direct inspection of stored records.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100288"
    },
    {
      "rank": 570,
      "cve_id": "CVE-2026-100756",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Incorrect boundary conditions in the Audio/Video: Playback component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100756"
    },
    {
      "rank": 571,
      "cve_id": "CVE-2026-100758",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Sandbox escape in the DOM: Navigation component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100758"
    },
    {
      "rank": 572,
      "cve_id": "CVE-2026-100759",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Uninitialized memory in the Storage: Quota Manager component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100759"
    },
    {
      "rank": 573,
      "cve_id": "CVE-2026-100760",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Sandbox escape in the Security: Process Sandboxing component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100760"
    },
    {
      "rank": 574,
      "cve_id": "CVE-2026-100763",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Incorrect boundary conditions in the Graphics: WebGPU component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100763"
    },
    {
      "rank": 575,
      "cve_id": "CVE-2026-100771",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Undefined behavior in the DOM: Streams component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100771"
    },
    {
      "rank": 576,
      "cve_id": "CVE-2026-100775",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Sandbox escape in the Graphics component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100775"
    },
    {
      "rank": 577,
      "cve_id": "CVE-2026-100781",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100781"
    },
    {
      "rank": 578,
      "cve_id": "CVE-2026-100787",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Sandbox escape in the XUL component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100787"
    },
    {
      "rank": 579,
      "cve_id": "CVE-2026-100788",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Invalid pointer in the JavaScript: WebAssembly component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100788"
    },
    {
      "rank": 580,
      "cve_id": "CVE-2026-100792",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "JIT miscompilation in the JavaScript: WebAssembly component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100792"
    },
    {
      "rank": 581,
      "cve_id": "CVE-2026-100793",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "JIT miscompilation in the JavaScript Engine component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100793"
    },
    {
      "rank": 582,
      "cve_id": "CVE-2026-100794",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Sandbox escape due to incorrect boundary conditions in the Internationalization component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100794"
    },
    {
      "rank": 583,
      "cve_id": "CVE-2026-100798",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Cryptography misuse in Storage: Quota Manager component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100798"
    },
    {
      "rank": 584,
      "cve_id": "CVE-2026-100803",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Same-origin policy bypass in the WebExtensions component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100803"
    },
    {
      "rank": 585,
      "cve_id": "CVE-2026-100808",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Mitigation bypass in the DOM: Service Workers component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100808"
    },
    {
      "rank": 586,
      "cve_id": "CVE-2026-100809",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Same-origin policy bypass in the DevTools component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100809"
    },
    {
      "rank": 587,
      "cve_id": "CVE-2026-100810",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Other issue in the DevTools component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100810"
    },
    {
      "rank": 588,
      "cve_id": "CVE-2026-100816",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Site isolation issue in the DOM: Networking component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100816"
    },
    {
      "rank": 589,
      "cve_id": "CVE-2026-100817",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Other issue in the JavaScript: WebAssembly component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100817"
    },
    {
      "rank": 590,
      "cve_id": "CVE-2026-100821",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Site isolation issue in the Panning and Zooming component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100821"
    },
    {
      "rank": 591,
      "cve_id": "CVE-2026-100822",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Spoofing issue in the Networking: HTTP component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100822"
    },
    {
      "rank": 592,
      "cve_id": "CVE-2026-100823",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Spoofing issue in the Downloads component in Firefox for Android",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100823"
    },
    {
      "rank": 593,
      "cve_id": "CVE-2026-100828",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Mitigation bypass in the Bookmarks & History component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100828"
    },
    {
      "rank": 594,
      "cve_id": "CVE-2026-100829",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Mitigation bypass in the DOM: Security component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100829"
    },
    {
      "rank": 595,
      "cve_id": "CVE-2026-100830",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Mitigation bypass in the DOM: Navigation component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100830"
    },
    {
      "rank": 596,
      "cve_id": "CVE-2026-102310",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in Payments in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102310"
    },
    {
      "rank": 597,
      "cve_id": "CVE-2026-102312",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "UI misrepresentation in Omnibox in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102312"
    },
    {
      "rank": 598,
      "cve_id": "CVE-2026-102320",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in CORS in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102320"
    },
    {
      "rank": 599,
      "cve_id": "CVE-2026-102329",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-79",
      "title": "Cross-site scripting in WebUI in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102329"
    },
    {
      "rank": 600,
      "cve_id": "CVE-2026-102330",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in SiteIsolation in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102330"
    },
    {
      "rank": 601,
      "cve_id": "CVE-2026-102728",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "NetX Duo",
      "cwe": "CWE-126",
      "title": "Two client-side TLS/DTLS handshake parsers in NetX Secure read fields from a server-supplied message before validating that the message is long enough to contain them. Both are bounded out-of-bounds reads on a remotely reachable path, both are reached from a TLS or DTLS client connecting to a malicious or malformed server, and both have the same shape: the bounds check exists and returns the correct status, but it runs after the read it is meant to guard.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102728"
    },
    {
      "rank": 602,
      "cve_id": "CVE-2026-102758",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "NetX Duo",
      "cwe": "CWE-126",
      "title": "The `_nx_secure_x509_asn1_tlv_block_parse()` function parses ASN.1 TLV (tag-length-value) blocks out of DER-encoded data. It is the primitive underneath all X.509 certificate parsing in NetX Secure, and therefore runs on certificates supplied by a remote peer during the TLS handshake. The function reads the one-byte ASN.1 tag from the caller's buffer *before* checking that the buffer holds at least one byte. When a caller passes a remaining length of zero, the guard correctly returns `NX_SECURE_X509_ASN1_LENGTH_TOO_LONG`, but the read has already happened one byte past the end of the buffer. code: nx_secure/src/nx_secure_x509_asn1_tlv_block_parse.c ``` UINT _nx_secure_x509_asn1_tlv_block_parse(const UCHAR *buffer, ULONG *buffer_length, USHORT *tlv_type, USHORT *tlv_tag_class, ULONG *tlv_length, const UCHAR **tlv_data, ULONG *header_length) { UINT current_index; USHORT current_tag; ULONG length; ULONG length_bytes; current_index = 0; current_tag = buffer[current_index]; /* <-- read before the bounds check */ if (*buffer_length < 1) { return(NX_SECURE_X509_ASN1_LENGTH_TOO_LONG); } ``` The remainder of the function is correctly ordered. The multi-byte length path is guarded by `length_bytes > 4 || length_bytes > *buffer_length` before its read loop, the decoded value is checked against `length > *buffer_length`, and the second single-byte length read follows its own `*buffer_length < 1` guard. The tag read is the only load placed ahead of its check.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102758"
    },
    {
      "rank": 603,
      "cve_id": "CVE-2026-102796",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wikimedia Foundation",
      "product": "Mediawiki - UserPageViewTracker Extension",
      "cwe": "CWE-89",
      "title": "Unauthenticated SQL injection in UserPageViewTracker via filterusers and ignoreusers parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102796"
    },
    {
      "rank": 604,
      "cve_id": "CVE-2026-103044",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Wikimedia Foundation",
      "product": "Mediawiki - EasyTimeline extension",
      "cwe": "CWE-91",
      "title": "EasyTimeline should not serve image maps as application/xml",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103044"
    },
    {
      "rank": 605,
      "cve_id": "CVE-2026-103045",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Wikimedia Foundation",
      "product": "Mediawiki - Refreshed skin",
      "cwe": "CWE-79",
      "title": "XSS in Refreshed skin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103045"
    },
    {
      "rank": 606,
      "cve_id": "CVE-2026-103046",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Wikimedia Foundation",
      "product": "Mediawiki - WikiLambda Extension",
      "cwe": "CWE-79",
      "title": "WikifunctionsFragmentRenderer does unsafe string replacements on user-provided HTML",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103046"
    },
    {
      "rank": 607,
      "cve_id": "CVE-2026-103047",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Wikimedia Foundation",
      "product": "Mediawiki - CentralAuth extension",
      "cwe": "CWE-79",
      "title": "XSS through i18n message in CentralAuth",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103047"
    },
    {
      "rank": 608,
      "cve_id": "CVE-2026-103048",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Wikimedia Foundation",
      "product": "Mediawiki - Collection extension",
      "cwe": "CWE-601",
      "title": "Open Redirect in Special:Book",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103048"
    },
    {
      "rank": 609,
      "cve_id": "CVE-2026-103049",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Wikimedia Foundation",
      "product": "Mediawiki - Cargo extension",
      "cwe": "CWE-79",
      "title": "XSS in Cargo's Special:CargoQuery page due to unsanitized table headers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103049"
    },
    {
      "rank": 610,
      "cve_id": "CVE-2026-103050",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Wikimedia Foundation",
      "product": "Mediawiki - MassMessage extension",
      "cwe": "CWE-79",
      "title": "Stored i18n XSS in MassMessage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103050"
    },
    {
      "rank": 611,
      "cve_id": "CVE-2026-103051",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Wikimedia Foundation",
      "product": "Mediawiki - CentralNotice extension",
      "cwe": "CWE-79",
      "title": "Stored i18n XSSs in CentralNotice",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103051"
    }
  ],
  "transactions": [
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-86950",
      "detail": "ADDED TO KEV — CVE-2026-86950 (Apple iOS and iPadOS). Remediation due October 2, 2026."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-100303",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-100303 (TDuckCloud tduck-survey-form). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-100310",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-100310 (GNU libextractor). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-100312",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-100312 (mathurvishal CloudClassroom-PHP-Project). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-100315",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-100315 (mathurvishal CloudClassroom-PHP-Project). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-100389",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-100389 (GestSup). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-101139",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-101139 (Webkul Bagisto). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-101141",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-101141 (Eleveo Call Recording Software). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-101143",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-101143 (Eleveo Quality Management). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-101144",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-101144 (Eleveo Call Recording Software). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-101146",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-101146 (Eleveo Quality Management). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-101187",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-101187 (Ziroom ZHOME A0101). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-101260",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-101260 (Ziroom ZHOME A0101). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-101262",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-101262 (Ziroom ZHOME A0101). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-102372",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-102372 (GestSup). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-102373",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-102373 (GestSup). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-102374",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-102374 (GestSup). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-3832",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-3832 (gnutls). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-3833",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-3833 (gnutls). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-4878",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-4878 (Red Hat Enterprise Linux 10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48864",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48864 (Red Hat Enterprise Linux 10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-50291",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-50291 (AcademySoftwareFoundation OpenImageIO). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55193",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55193 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-57228",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-57228 (OISF suricata). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58016",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58016 (GNOME GLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59156",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59156 (AcademySoftwareFoundation OpenImageIO). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59181",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59181 (AcademySoftwareFoundation OpenImageIO). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59956",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59956 (AcademySoftwareFoundation OpenImageIO). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-62368",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-62368 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-63419",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-63419 (AcademySoftwareFoundation OpenImageIO). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-63420",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-63420 (AcademySoftwareFoundation OpenImageIO). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-63422",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-63422 (AcademySoftwareFoundation OpenImageIO). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-63493",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-63493 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-63498",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-63498 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-63635",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-63635 (AcademySoftwareFoundation OpenImageIO). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-63638",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-63638 (AcademySoftwareFoundation OpenImageIO). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-65969",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-65969 (AcademySoftwareFoundation OpenImageIO). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-65970",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-65970 (AcademySoftwareFoundation OpenImageIO). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67293",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67293 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67549",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67549 (AcademySoftwareFoundation OpenImageIO). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-68580",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-68580 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73253",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73253 (cesanta mongoose). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73254",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73254 (cesanta mongoose). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73255",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73255 (cesanta mongoose). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73256",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73256 (cesanta mongoose). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73257",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73257 (cesanta mongoose). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73258",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73258 (cesanta mongoose). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73259",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73259 (cesanta mongoose). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-75926",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-75926 (gohugoio hugo). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-77242",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-77242 (sooperset mcp-atlassian). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-77243",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-77243 (sooperset mcp-atlassian). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-77244",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-77244 (sooperset mcp-atlassian). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-77249",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-77249 (sooperset mcp-atlassian). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-77250",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-77250 (sooperset mcp-atlassian). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-77251",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-77251 (sooperset mcp-atlassian). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-77255",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-77255 (sooperset mcp-atlassian). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-77258",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-77258 (sooperset mcp-atlassian). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-77259",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-77259 (sooperset mcp-atlassian). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-77260",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-77260 (sooperset mcp-atlassian). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-77262",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-77262 (sooperset mcp-atlassian). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-77265",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-77265 (sooperset mcp-atlassian). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-77267",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-77267 (sooperset mcp-atlassian). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-77268",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-77268 (sooperset mcp-atlassian). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-77269",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-77269 (sooperset mcp-atlassian). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-79718",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-79718 (Netron). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-79719",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-79719 (Netron). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-84206",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-84206 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-88056",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-88056 (angular). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-88057",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-88057 (angular). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-88058",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-88058 (angular). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-88059",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-88059 (angular). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-88060",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-88060 (angular). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-88894",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-88894 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-93355",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-93355 (BerriAI litellm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-95844",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-95844 (moquette-io moquette). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-97896",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-97896 (krayin laravel-crm). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-65660",
      "detail": "DUE DATE PASSED — CVE-2026-65660 (Microsoft SharePoint Enterprise Server 2016). CISA remediation deadline was September 28, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-67279",
      "detail": "DUE DATE PASSED — CVE-2026-67279 (Mikrotik RouterOS). CISA remediation deadline was September 28, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-87902",
      "detail": "DUE DATE PASSED — CVE-2026-87902 (WordPress). CISA remediation deadline was September 28, 2026; still in catalog."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2017-20051",
      "detail": "RESCORED — CVE-2017-20051 (InnoSetup Installer). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2023-6394",
      "detail": "RESCORED — CVE-2023-6394 (Red Hat build of Quarkus 3.2.9.Final). CVSS 7.4 → 9.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-58376",
      "detail": "RESCORED — CVE-2024-58376 (renovatebot renovate). CVSS 9.3 → 8.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-31356",
      "detail": "RESCORED — CVE-2025-31356 (Intel(R) Trust Domain Extensions (Intel(R) TDX)). CVSS 5.6 → 5.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-101263",
      "detail": "RESCORED — CVE-2026-101263 (Ziroom ZHOME A0101). CVSS 9.4 → 8.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-101264",
      "detail": "RESCORED — CVE-2026-101264 (Ziroom ZHOME A0101). CVSS 9.4 → 8.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-101265",
      "detail": "RESCORED — CVE-2026-101265 (Intelbras TIP 125i). CVSS 2.3 → 1.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-101277",
      "detail": "RESCORED — CVE-2026-101277 (Trusted Domain Project OpenDKIM). CVSS 6.9 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-17504",
      "detail": "RESCORED — CVE-2026-17504 (IBM PowerVM Hypervisor). CVSS 5.1 → 4.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-51772",
      "detail": "RESCORED — CVE-2026-51772. CVSS 8.1 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-57228",
      "detail": "RESCORED — CVE-2026-57228 (OISF suricata). CVSS 8.2 → 9.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-62368",
      "detail": "RESCORED — CVE-2026-62368 (grokability snipe-it). CVSS 8.1 → 8.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-63498",
      "detail": "RESCORED — CVE-2026-63498 (grokability snipe-it). CVSS 8.7 → 5.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-65114",
      "detail": "RESCORED — CVE-2026-65114 (NVIDIA Infrastructure Controller). CVSS 8.3 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-65117",
      "detail": "RESCORED — CVE-2026-65117 (NVIDIA Infrastructure Controller). CVSS 5 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-65118",
      "detail": "RESCORED — CVE-2026-65118 (NVIDIA Infrastructure Controller). CVSS 7.5 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-65121",
      "detail": "RESCORED — CVE-2026-65121 (NVIDIA Infrastructure Controller). CVSS 8.2 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-65124",
      "detail": "RESCORED — CVE-2026-65124 (NVIDIA Infrastructure Controller). CVSS 5.9 → 8.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-65125",
      "detail": "RESCORED — CVE-2026-65125 (NVIDIA Infrastructure Controller). CVSS 6.6 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-65126",
      "detail": "RESCORED — CVE-2026-65126 (NVIDIA Infrastructure Controller). CVSS 5 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-65127",
      "detail": "RESCORED — CVE-2026-65127 (NVIDIA Infrastructure Controller). CVSS 4.1 → 4.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-65129",
      "detail": "RESCORED — CVE-2026-65129 (NVIDIA Infrastructure Controller). CVSS 6.7 → 8.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-65130",
      "detail": "RESCORED — CVE-2026-65130 (NVIDIA Infrastructure Controller). CVSS 8 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-69559",
      "detail": "RESCORED — CVE-2026-69559 (Microsoft Teams for Android). CVSS 5.8 → 6.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-69805",
      "detail": "RESCORED — CVE-2026-69805 (Microsoft Visual Studio 2022 version 17.14). CVSS 7.5 → 8.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-69854",
      "detail": "RESCORED — CVE-2026-69854 (Microsoft Spring Cloud Azure). CVSS 9 → 8.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-77265",
      "detail": "RESCORED — CVE-2026-77265 (sooperset mcp-atlassian). CVSS 5.9 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-77909",
      "detail": "RESCORED — CVE-2026-77909 (Microsoft Azure CycleCloud 8.9.2). CVSS 7.7 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-78545",
      "detail": "RESCORED — CVE-2026-78545 (Okta Access Gateway). CVSS 6.6 → 7.2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-78550",
      "detail": "RESCORED — CVE-2026-78550 (Okta Access Gateway). CVSS 6.6 → 7.2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-88059",
      "detail": "RESCORED — CVE-2026-88059 (angular). CVSS 4 → 5.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-88420",
      "detail": "RESCORED — CVE-2026-88420. CVSS 6.1 → 5.4 (NVD)."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-102010",
      "detail": "PATCH SHIPPED — CVE-2026-102010 (Red Hat Hardened Images). Fixed in Red Hat Hardened Images 13.5.0-0.2.hum1."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-57759",
      "detail": "PATCH SHIPPED — CVE-2026-57759 (Metagauss ProfileGrid). Fixed in ProfileGrid 6.0.0.3."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
