{
  "day": "2026-09-30",
  "boundary": "UTC calendar day",
  "published_count": 636,
  "by_severity": {
    "CRITICAL": 54,
    "HIGH": 296,
    "MEDIUM": 226,
    "LOW": 40
  },
  "kev_count": 1,
  "exploit_reference_count": 0,
  "awaiting_enrichment_count": 20,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-76504",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": true,
      "kev_due_at": "2026-10-03",
      "vendor": "Cisco",
      "product": "Cisco Catalyst SD-WAN Manager",
      "cwe": "CWE-177",
      "title": "Cisco Catalyst SD-WAN Manager System Account Authorization Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76504"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-102911",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.01779,
      "epss_percentile": 0.77405,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zosmaai",
      "product": "pi-llm-wiki",
      "cwe": "CWE-77",
      "title": "zosmaai pi-llm-wiki wiki_capture_source MCP tool index.ts os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102911"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-103056",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0146,
      "epss_percentile": 0.72586,
      "kev": false,
      "kev_due_at": null,
      "vendor": "beenuar",
      "product": "AiSOC",
      "cwe": "CWE-78",
      "title": "AiSOC 7.2.0 before 12.0.0 Command Injection via CrowdStrike RTR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103056"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-102874",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01324,
      "epss_percentile": 0.69834,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HKUDS",
      "product": "AnyTool",
      "cwe": "CWE-77",
      "title": "HKUDS AnyTool Execute Endpoint main.py subprocess.run os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102874"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-102906",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.01067,
      "epss_percentile": 0.6347,
      "kev": false,
      "kev_due_at": null,
      "vendor": "0xshariq",
      "product": "github-mcp-server",
      "cwe": "CWE-77",
      "title": "0xshariq github-mcp-server Git Remove MCP Tool github.ts child_process.exec os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102906"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-75098",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.009,
      "epss_percentile": 0.58128,
      "kev": false,
      "kev_due_at": null,
      "vendor": "productdesignerapp",
      "product": "Product Designer App",
      "cwe": "CWE-22",
      "title": "Product Designer App <= 1.1.3 - Unauthenticated Arbitrary File Read via 'svg' Parameter in pdapp-render-design",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75098"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-103088",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00689,
      "epss_percentile": 0.50942,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jknack",
      "product": "handlebars.java",
      "cwe": "CWE-24",
      "title": "Handlebars.java before 4.5.5 allows directory traversal. In handlebars-springmvc 4.5.3 and 4.5.4, the path-containment fix for CVE-2026-63490 validates template locations as raw percent-encoded strings, whereas the template file is opened through a URL handler that percent-decodes the path. In a Spring MVC application with a file: template prefix and a request-derived view name, a percent-encoded traversal such as %2e%2e/ bypasses both the view-resolver check and the loader-side containment and reads files outside the configured template base directory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103088"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-89294",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00646,
      "epss_percentile": 0.49032,
      "kev": false,
      "kev_due_at": null,
      "vendor": "croixhaug",
      "product": "Simply Schedule Appointments",
      "cwe": "CWE-98",
      "title": "Simply Schedule Appointments <= 1.6.12.27 - Authenticated (Subscriber+) Local File Inclusion via 'ssa_locale' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89294"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-103110",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00608,
      "epss_percentile": 0.47117,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pexip",
      "product": "Infinity",
      "cwe": "CWE-787",
      "title": "Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation that allows a remote attacker to execute code remotely as an unprivileged user on a Pexip Infinity Conferencing Node.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103110"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-102454",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00562,
      "epss_percentile": 0.4463,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DigiWin",
      "product": "EasyFlow .NET",
      "cwe": "CWE-434",
      "title": "DigiWin｜EasyFlow .NET - Arbitrary File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102454"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-94052",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00529,
      "epss_percentile": 0.42567,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache MINA SSHD",
      "cwe": "CWE-304",
      "title": "Apache MINA SSHD: LDAP password authentication ineffective",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94052"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-94053",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00529,
      "epss_percentile": 0.42568,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache MINA SSHD",
      "cwe": "CWE-90",
      "title": "Apache MINA SSHD: LDAP injection in sshd-ldap",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94053"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-102455",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00508,
      "epss_percentile": 0.41152,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DigiWin",
      "product": "EasyFlow .NET",
      "cwe": "CWE-502",
      "title": "DigiWin｜EasyFlow .NET - Insecure Deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102455"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-77185",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00466,
      "epss_percentile": 0.37936,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache MINA SSHD",
      "cwe": "CWE-305",
      "title": "Apache MINA SSHD: Asynchronous authentication can bypass signature verification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77185"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-93994",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00457,
      "epss_percentile": 0.3727,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache MINA SSHD",
      "cwe": "CWE-304",
      "title": "Apache MINA SSHD: Repeated-publickey policy bypass on server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93994"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-78229",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00434,
      "epss_percentile": 0.35328,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PFU Limited",
      "product": "Image Scanner Driver for Linux (fi Series)",
      "cwe": "CWE-78",
      "title": "Image Scanner Driver for Linux contains an OS command injection vulnerability. An attacker who can log in to a Linux system where the affected product is installed may execute an arbitrary OS command by making certain preparations.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78229"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-102458",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00425,
      "epss_percentile": 0.34449,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DigiWin",
      "product": "EasyFlow .NET",
      "cwe": "CWE-306",
      "title": "DigiWin｜EasyFlow .NET - Missing Authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102458"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-86134",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00422,
      "epss_percentile": 0.34197,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Fireware OS",
      "cwe": "CWE-476",
      "title": "Fireware OS Pre-Authentication NULL Pointer Dereference Allows Remote Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86134"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-93996",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00411,
      "epss_percentile": 0.32906,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache MINA SSHD",
      "cwe": "CWE-770",
      "title": "Apache MINA SSHD: Memory exhaustion DoS via unbounded SCP command line read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93996"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-103055",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00405,
      "epss_percentile": 0.32265,
      "kev": false,
      "kev_due_at": null,
      "vendor": "beenuar",
      "product": "AiSOC",
      "cwe": "CWE-321",
      "title": "AiSOC 7.5.0 before 12.0.0 Authentication Bypass via Hard-coded JWT Secret",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103055"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-102509",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00401,
      "epss_percentile": 0.31856,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache PLC4X",
      "cwe": "CWE-674",
      "title": "Apache PLC4X, Apache PLC4X: Pre-authentication resource exhaustion in the OPC UA driver and the Java SPI parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102509"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-79625",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.004,
      "epss_percentile": 0.31714,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CODESYS",
      "product": "Control RTE (SL)",
      "cwe": "CWE-362",
      "title": "Improper Synchronization in Monitoring in CODESYS Control Runtime",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79625"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-103237",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00389,
      "epss_percentile": 0.30535,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-20",
      "title": "MISP: Nested Model Alias Key Bypasses Sanitization to Modify Cross-Tenant Rows",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103237"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-94002",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00385,
      "epss_percentile": 0.30078,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache MINA SSHD",
      "cwe": "CWE-770",
      "title": "Apache MINA SSHD: Memory exhaustion in SFTP client via unsolicited SFTP replies",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94002"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-102457",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0038,
      "epss_percentile": 0.29547,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DigiWin",
      "product": "EasyFlow .NET",
      "cwe": "CWE-22",
      "title": "DigiWin｜EasyFlow .NET - Arbitrary File Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102457"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-103235",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00363,
      "epss_percentile": 0.27679,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-639",
      "title": "MISP Event Delegation Mass Assignment Allows Retargeting Delegation to Arbitrary Events",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103235"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-91051",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00358,
      "epss_percentile": 0.27189,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "EWWW Image Optimizer",
      "cwe": "CWE-502",
      "title": "EWWW Image Optimizer 8.6.0 - 8.7.7 - Author+ PHP Object Injection via 'eio_page_settings' Post Meta",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91051"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-102804",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00347,
      "epss_percentile": 0.25845,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nothings",
      "product": "stb",
      "cwe": "CWE-189",
      "title": "Nothings stb stb_hexwave.h hexwave_init integer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102804"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-102805",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00347,
      "epss_percentile": 0.25845,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nothings",
      "product": "stb",
      "cwe": "CWE-189",
      "title": "Nothings stb Image Encoding stb_image_write.h stbi_write_tga_core integer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102805"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-92867",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00344,
      "epss_percentile": 0.2551,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pgpool Global Development Group",
      "product": "Pgpool-II",
      "cwe": "CWE-787",
      "title": "An out-of-bounds write vulnerability exists in Pgpool-II , which may allow an authenticated attacker to cause abnormal process termination or arbitrary code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92867"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-94029",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00344,
      "epss_percentile": 0.2546,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache MINA SSHD",
      "cwe": "CWE-770",
      "title": "Apache MINA SSHD: Memory exhaustion in SFTP v6 check-file-name/check-file-handle extension",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94029"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-97150",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00336,
      "epss_percentile": 0.24565,
      "kev": false,
      "kev_due_at": null,
      "vendor": "baserCMS Users Community",
      "product": "BcAddonMigrator",
      "cwe": "CWE-829",
      "title": "When converting baserCMS4-style addons to baserCMS5-style ones, BcAddonMigrator includes \"config.php\" from the addon, which means the PHP code in the file is executed. Arbitrary files on the system may be read or deleted by an administrative user.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97150"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-102843",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.0033,
      "epss_percentile": 0.23665,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gedelumbung",
      "product": "HospitalManagement",
      "cwe": "CWE-22",
      "title": "gedelumbung HospitalManagement Endpoint data_galeri.php hapus path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102843"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-102510",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00328,
      "epss_percentile": 0.23467,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache PLC4X",
      "cwe": "CWE-129",
      "title": "Apache PLC4X: Go binding: unbounded allocation and framing failures on wire-controlled lengths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102510"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-93462",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00325,
      "epss_percentile": 0.23169,
      "kev": false,
      "kev_due_at": null,
      "vendor": "baserCMS User Community",
      "product": "baserCMS",
      "cwe": "CWE-306",
      "title": "A missing authentication for critical function vulnerability exists in baserCMS. If this vulnerability is exploited, a remote attacker may obtain sensitive information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93462"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-92870",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0032,
      "epss_percentile": 0.22647,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pgpool Global Development Group",
      "product": "Pgpool-II",
      "cwe": "CWE-121",
      "title": "A stack-based buffer overflow vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal process termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92870"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-103102",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0032,
      "epss_percentile": 0.22588,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pexip",
      "product": "Infinity",
      "cwe": "CWE-770",
      "title": "Pexip Infinity before 41.0 is affected by improper input validation in the signaling implementation which allows a remote attacker to trigger a software abort resulting in a denial of service. Exploitation of this issue requires accessing a gateway call from a WebRTC/API client.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103102"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-103087",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0032,
      "epss_percentile": 0.22581,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gosub-io",
      "product": "gosub-engine",
      "cwe": "CWE-674",
      "title": "Uncontrolled recursion in the Gosub browser engine (gosub-engine) through 0.1.0 and main before commit 46868b3 allows a remote attacker to cause a Denial of Service (stack exhaustion and application crash) via an SVG document containing an excessive number of deeply nested elements. Because the engine does not limit the nesting depth of processed SVG nodes, rendering such a document overflows the thread stack and terminates the application. The malicious SVG can be embedded through the SRC attribute of an IMG element, and thus exploitation only requires the victim to visit an attacker-controlled web page.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103087"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-92873",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00314,
      "epss_percentile": 0.21962,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pgpool Global Development Group",
      "product": "Pgpool-II",
      "cwe": "CWE-303",
      "title": "Pgpool-II contains an incorrect implementation of an authentication algorithm, which may allow an unauthenticated attacker to promote an arbitrary watchdog node to the leader node.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92873"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-103099",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00313,
      "epss_percentile": 0.21899,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pexip",
      "product": "Infinity",
      "cwe": "CWE-617",
      "title": "Pexip Infinity before 41.1 is affected by improper input validation in the media implementation that allows a remote attacker to trigger a software abort resulting in a denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103099"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-103104",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00313,
      "epss_percentile": 0.21898,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pexip",
      "product": "Infinity",
      "cwe": "CWE-617",
      "title": "Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation which allows a remote attacker to trigger a software abort resulting in a denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103104"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-103108",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00313,
      "epss_percentile": 0.21899,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pexip",
      "product": "Infinity",
      "cwe": "CWE-617",
      "title": "Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger a software abort resulting in a denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103108"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-102845",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00311,
      "epss_percentile": 0.21679,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gedelumbung",
      "product": "HospitalManagement",
      "cwe": "CWE-200",
      "title": "gedelumbung HospitalManagement HTTP Response index.php error_reporting information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102845"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-97196",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00296,
      "epss_percentile": 0.20138,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Liquid Web / StellarWP",
      "product": "GiveWP",
      "cwe": "CWE-1289",
      "title": "WordPress GiveWP plugin <= 4.16.9 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97196"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-92871",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0029,
      "epss_percentile": 0.19468,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pgpool Global Development Group",
      "product": "Pgpool-II",
      "cwe": "CWE-476",
      "title": "A NULL pointer dereference vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal termination of the watchdog process.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92871"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-102586",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00286,
      "epss_percentile": 0.19035,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "moodle",
      "cwe": "CWE-79",
      "title": "Moodle: xss via password reset link due to insufficient username escaping",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102586"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-102842",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00276,
      "epss_percentile": 0.18053,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gedelumbung",
      "product": "HospitalManagement",
      "cwe": "CWE-284",
      "title": "gedelumbung HospitalManagement KCFinder File Manager app_user_login_model.php cekUserLogin unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102842"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-6806",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00273,
      "epss_percentile": 0.17753,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stylemix",
      "product": "Motors – Car Dealership & Classified Listings Plugin",
      "cwe": "CWE-89",
      "title": "Motors <= 1.4.109 - Unauthenticated Blind SQL Injection via 'stm_lat'/'stm_lng' Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6806"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-102847",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00273,
      "epss_percentile": 0.17764,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gedelumbung",
      "product": "HospitalManagement",
      "cwe": "CWE-79",
      "title": "gedelumbung HospitalManagement Guest Book buku_tamu.php kirim cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102847"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-102456",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00272,
      "epss_percentile": 0.17727,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DigiWin",
      "product": "EasyFlow .NET",
      "cwe": "CWE-89",
      "title": "DigiWin｜EasyFlow .NET - SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102456"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-93995",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00271,
      "epss_percentile": 0.17489,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache MINA SSHD",
      "cwe": "CWE-20",
      "title": "Apache MINA SSHD: Remote execution of JGit \"archive -o=file.zip\" can write file on the server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93995"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-102910",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.17174,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Online Reviewer Management System",
      "cwe": "CWE-74",
      "title": "SourceCodester Online Reviewer Management System exam-delete.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102910"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-102913",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.17175,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Car Driving School Management System",
      "cwe": "CWE-74",
      "title": "SourceCodester Car Driving School Management System Master.php save_enrollment sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102913"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-103101",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00268,
      "epss_percentile": 0.17129,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pexip",
      "product": "Infinity",
      "cwe": "CWE-770",
      "title": "Pexip Infinity 30.0 through 40.x before 41.0 is affected by improper input validation in the web server that allows a malicious attacker to render a Pexip Infinity node inaccessible.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103101"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-103100",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.16337,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pexip",
      "product": "Infinity",
      "cwe": "CWE-617",
      "title": "Pexip Infinity before 40.1 is affected by improper input validation in the signaling implementation that allows a malicious attacker to trigger a software abort resulting in a denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103100"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-102908",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.1639,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Online Reviewer Management System",
      "cwe": "CWE-74",
      "title": "SourceCodester Online Reviewer Management System questions-view.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102908"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-102909",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.16388,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Online Reviewer Management System",
      "cwe": "CWE-74",
      "title": "SourceCodester Online Reviewer Management System btn_functions.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102909"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-102577",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.16433,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "moodle",
      "cwe": "CWE-918",
      "title": "Moodle: ssrf risk in url downloader via ipv4-mapped ipv6 address bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102577"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-102844",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00258,
      "epss_percentile": 0.15802,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gedelumbung",
      "product": "HospitalManagement",
      "cwe": "CWE-285",
      "title": "gedelumbung HospitalManagement laporan_data_pasien.php detail authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102844"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-97347",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00254,
      "epss_percentile": 0.15273,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kazukiyanamoto",
      "product": "Post Views Stats Counter",
      "cwe": "CWE-79",
      "title": "Post Views Stats Counter <= 1.1.7 - Unauthenticated Stored Cross-Site Scripting via User-Agent Header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97347"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-103057",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00253,
      "epss_percentile": 0.15229,
      "kev": false,
      "kev_due_at": null,
      "vendor": "beenuar",
      "product": "AiSOC",
      "cwe": "CWE-306",
      "title": "AiSOC 5.1.0 before 12.0.0 Missing Authentication on Realtime Service Internal Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103057"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-92869",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0025,
      "epss_percentile": 0.14759,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pgpool Global Development Group",
      "product": "Pgpool-II",
      "cwe": "CWE-787",
      "title": "An out-of-bounds write vulnerability exists in Pgpool-II, which may allow an authenticated attacker to cause abnormal process termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92869"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-96649",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00247,
      "epss_percentile": 0.14393,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpshuffle",
      "product": "Frontend Post Submission Manager Lite – Guest Post and Frontend Submission Forms",
      "cwe": "CWE-79",
      "title": "Frontend Post Submission Manager Lite <= 1.3.4 - Unauthenticated Stored DOM-Based Cross-Site Scripting via post_content Parameter (data-label DOM Sink)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96649"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-102578",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00247,
      "epss_percentile": 0.1446,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "moodle",
      "cwe": "CWE-89",
      "title": "Moodle: sql injection in question bank web service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102578"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-103109",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00243,
      "epss_percentile": 0.14023,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pexip",
      "product": "Infinity",
      "cwe": "CWE-787",
      "title": "Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger memory corruption or a software abort resulting in a denial of service. A crafted media stream may result in a controlled abort during processing, and has the potential to achieve memory corruption.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103109"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-10764",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.13386,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IQSIGHT",
      "product": "BVMS",
      "cwe": "CWE-321",
      "title": "Information disclosure in BVMS 4.5 up to 12.3",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10764"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-103053",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00237,
      "epss_percentile": 0.1331,
      "kev": false,
      "kev_due_at": null,
      "vendor": "beenuar",
      "product": "AiSOC",
      "cwe": "CWE-306",
      "title": "AiSOC 9.0.0 before 12.0.0 Missing Authentication on Actions Service Response-Action API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103053"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-102583",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00236,
      "epss_percentile": 0.13173,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "moodle",
      "cwe": "CWE-425",
      "title": "Moodle: incorrect capability check in ai generate image web service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102583"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-102587",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00233,
      "epss_percentile": 0.12815,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "moodle",
      "cwe": "CWE-204",
      "title": "Moodle: user list filters bypass profile field visibility",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102587"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-102580",
      "cvss_base": 2.2,
      "cvss_severity": "LOW",
      "epss_score": 0.00233,
      "epss_percentile": 0.12827,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "moodle",
      "cwe": "CWE-470",
      "title": "Moodle: arbitrary class instantiation via report builder audience classname",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102580"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-102846",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00227,
      "epss_percentile": 0.12157,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gedelumbung",
      "product": "HospitalManagement",
      "cwe": "CWE-266",
      "title": "gedelumbung HospitalManagement Configuration sistem.php simpan improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102846"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-16596",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00224,
      "epss_percentile": 0.1174,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpdirectorykit",
      "product": "WP Directory Kit",
      "cwe": "CWE-89",
      "title": "WP Directory Kit <= 1.5.4 - Authenticated (Custom+) SQL Injection via 'data_fields_list' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16596"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-103054",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00222,
      "epss_percentile": 0.11606,
      "kev": false,
      "kev_due_at": null,
      "vendor": "beenuar",
      "product": "AiSOC",
      "cwe": "CWE-639",
      "title": "AiSOC 10.0.0 before 12.0.0 Unauthorized Tenant Access via MSSP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103054"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-75873",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00218,
      "epss_percentile": 0.11011,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Zella Theme",
      "cwe": "CWE-434",
      "title": "Zella Theme < 2.6.3 - Unauthenticated Arbitrary File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75873"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-102579",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00217,
      "epss_percentile": 0.10985,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "moodle",
      "cwe": "CWE-359",
      "title": "Moodle: user profile information disclosure via grade web service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102579"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-102912",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00214,
      "epss_percentile": 0.10603,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Online Leave Management System",
      "cwe": "CWE-74",
      "title": "SourceCodester Online Leave Management System page reports sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102912"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-103111",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00206,
      "epss_percentile": 0.09583,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PCRE",
      "product": "PCRE2",
      "cwe": "CWE-787",
      "title": "PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103111"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-102582",
      "cvss_base": 2.2,
      "cvss_severity": "LOW",
      "epss_score": 0.00204,
      "epss_percentile": 0.0938,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "moodle",
      "cwe": "CWE-425",
      "title": "Moodle: manual enrolment page accessible when plugin disabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102582"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-102459",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.08938,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DigiWin",
      "product": "EasyFlow .NET",
      "cwe": "CWE-79",
      "title": "DigiWin｜EasyFlow .NET - Reflected Cross-site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102459"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-102584",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00196,
      "epss_percentile": 0.08362,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "moodle",
      "cwe": "CWE-425",
      "title": "Moodle: missing capability check allows unauthorised grade penalty recalculation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102584"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-102585",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00196,
      "epss_percentile": 0.08361,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "moodle",
      "cwe": "CWE-842",
      "title": "Moodle: group validation missing when enrolling user to course",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102585"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-92712",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.0808,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rockiger",
      "product": "ReactPress – Create React App for WordPress",
      "cwe": "CWE-79",
      "title": "ReactPress <= 3.4.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'permalink' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92712"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-93908",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.0808,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rameez_iqbal",
      "product": "Real Estate Manager – Property Listing and Agent Management",
      "cwe": "CWE-79",
      "title": "Real Estate Manager <= 7.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'before_price_text' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93908"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2025-14564",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0019,
      "epss_percentile": 0.0777,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ahsangadit",
      "product": "Viable URL Media Uploader",
      "cwe": "CWE-79",
      "title": "Viable URL Media Uploader <= 1.0.0 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-14564"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-86556",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.07481,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZTE",
      "product": "U30 Air",
      "cwe": "CWE-269",
      "title": "An information disclosure vulnerability in ZTE U30 Air product",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86556"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-103105",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00184,
      "epss_percentile": 0.07204,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pexip",
      "product": "Infinity",
      "cwe": "CWE-863",
      "title": "Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper access control on a product-internal API which allows an attacker with local access to a node within a Pexip Infinity installation to execute arbitrary code as an unprivileged user on another Pexip Infinity node.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103105"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-92872",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00184,
      "epss_percentile": 0.07201,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pgpool Global Development Group",
      "product": "Pgpool-II",
      "cwe": "CWE-532",
      "title": "Pgpool-II inserts sensitive information into log file, which may allow an authenticated attacker to obtain the cluster information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92872"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-93580",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00184,
      "epss_percentile": 0.07133,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "InPost PL",
      "cwe": "CWE-862",
      "title": "InPost for WooCommerce 1.7.5 - 1.9.7 - Unauthenticated Order Status Forgery via Shipment Webhook",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93580"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-51936",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0018,
      "epss_percentile": 0.06776,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zetetic",
      "product": "SQLCipher",
      "cwe": "CWE-89",
      "title": "Zetetic SQLCipher before 4.15.0 allows SQL injection. The sqlcipher_export convenience function can be used to copy the contents of one attached database into another. It is most often used to convert between plaintext and encrypted databases. It needs to do dynamic schema manipulation, and thus the function temporarily clears defensive restrictions during operation. A vulnerability in the handling of the source database name parameter made it possible for a caller to supply a crafted source name, which could execute statements that defensive mode would otherwise block. This could allow direct modifications to the sqlite_schema table and database corruption. SQLCipher 4.15.0 now strictly validates the source database name and prevents the bypass.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51936"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-83560",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00175,
      "epss_percentile": 0.0626,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "New User Approve",
      "cwe": "CWE-200",
      "title": "New User Approve 3.1.0 - 3.2.9 - Unauthenticated PII Disclosure via Zapier API Key Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83560"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-102588",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00173,
      "epss_percentile": 0.06034,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "moodle",
      "cwe": "CWE-346",
      "title": "Moodle: csrf in xml grade import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102588"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-85573",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.05968,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "All in One Files Upload",
      "cwe": "CWE-79",
      "title": "All in One Files Upload for WooCommerce 2.0.3 - 2.0.16 - Unauthenticated Stored XSS via SVG Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85573"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-92994",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.05967,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Verge3D Publishing and E-Commerce",
      "cwe": "CWE-79",
      "title": "Verge3D < 4.13.1 - Unauthenticated Stored XSS via File Storage API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92994"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-89193",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.05968,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Robin Image Optimizer",
      "cwe": "CWE-79",
      "title": "Robin Image Optimizer 2.0.0 - 2.0.7 - Unauthenticated Stored XSS via WebP URL Delivery HTML Parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89193"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-102581",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.05841,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "moodle",
      "cwe": "CWE-79",
      "title": "Moodle: xss in forum post templates due to insufficient escaping",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102581"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-102511",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00164,
      "epss_percentile": 0.05005,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache PLC4X",
      "cwe": "CWE-129",
      "title": "Apache PLC4X, Apache PLC4X, Apache PLC4X, Apache PLC4X: ADS discovery accepts spoofed responses and derives the connection target from them",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102511"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-6170",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.04113,
      "kev": false,
      "kev_due_at": null,
      "vendor": "boldthemes",
      "product": "Bold Page Builder",
      "cwe": "CWE-79",
      "title": "Bold Page Builder <= 5.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via bt_bb_css_image_grid 'images' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6170"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-6171",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.04113,
      "kev": false,
      "kev_due_at": null,
      "vendor": "boldthemes",
      "product": "Bold Page Builder",
      "cwe": "CWE-79",
      "title": "Bold Page Builder <= 5.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'target' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6171"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-6172",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.04112,
      "kev": false,
      "kev_due_at": null,
      "vendor": "boldthemes",
      "product": "Bold Page Builder",
      "cwe": "CWE-79",
      "title": "Bold Page Builder <= 5.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'caption' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6172"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-6173",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.04114,
      "kev": false,
      "kev_due_at": null,
      "vendor": "boldthemes",
      "product": "Bold Page Builder",
      "cwe": "CWE-79",
      "title": "Bold Page Builder <= 5.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'background_image' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6173"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-11895",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.04114,
      "kev": false,
      "kev_due_at": null,
      "vendor": "devitemsllc",
      "product": "HT Mega Addons for Elementor – Elementor Widgets & Template Builder",
      "cwe": "CWE-79",
      "title": "HT Mega Addons for Elementor <= 3.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Data Table 'display_options' Setting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11895"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-14876",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.04113,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nextendweb",
      "product": "Smart Slider 3",
      "cwe": "CWE-79",
      "title": "Smart Slider 3 <= 3.5.1.38 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-href' Attribute in Custom HTML Block",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14876"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-88037",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.04112,
      "kev": false,
      "kev_due_at": null,
      "vendor": "boldthemes",
      "product": "Bold Page Builder",
      "cwe": "CWE-79",
      "title": "Bold Page Builder <= 5.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via bt_bb_service title",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88037"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-85001",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.03719,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "EmbedPress",
      "cwe": "CWE-79",
      "title": "EmbedPress 4.4.9 - 4.6.6 - Contributor+ Stored XSS via Elementor Widget showTitle Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85001"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-85415",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.03719,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Audio Player Block",
      "cwe": "CWE-79",
      "title": "Audio Player Block 1.1.0 - 1.6.2 - Contributor+ Stored XSS via Audio Download URL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85415"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-87777",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.03718,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Hostinger Reach",
      "cwe": "CWE-79",
      "title": "Hostinger Reach 1.0.6 - 1.8.2 - Contributor+ Stored XSS via formId Elementor Widget Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87777"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-92424",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.03719,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Content Egg",
      "cwe": "CWE-79",
      "title": "Content Egg < 11.9.0 - Contributor+ Stored XSS via Import Queue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92424"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-82127",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00152,
      "epss_percentile": 0.03718,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Schema & Structured Data for WP & AMP",
      "cwe": "CWE-79",
      "title": "Schema & Structured Data for WP & AMP < 1.67 - Editor+ Stored XSS via Taxonomy Term Fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82127"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-92868",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00151,
      "epss_percentile": 0.03653,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pgpool Global Development Group",
      "product": "Pgpool-II",
      "cwe": "CWE-295",
      "title": "An improper certificate validation vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to bypass client certificate authentication.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92868"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-93463",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00151,
      "epss_percentile": 0.03604,
      "kev": false,
      "kev_due_at": null,
      "vendor": "baserCMS User Community",
      "product": "baserCMS",
      "cwe": "CWE-79",
      "title": "Cross-Site Scripting via Script Validation Bypass exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser may be caused.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93463"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-80333",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.03514,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Solace Extra",
      "cwe": "CWE-200",
      "title": "Solace Extra < 1.7.2 - Unauthenticated Non-Published Post Content Disclosure via Preview Routes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80333"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-88791",
      "cvss_base": 3.4,
      "cvss_severity": "LOW",
      "epss_score": 0.00148,
      "epss_percentile": 0.03421,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Safe Redirect Manager",
      "cwe": "CWE-601",
      "title": "Safe Redirect Manager < 2.3.0 - Open Redirect via Wildcard Redirect Rules",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88791"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-75823",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.03269,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "User Frontend",
      "cwe": "CWE-269",
      "title": "WP User Frontend 3.5.29 - 4.3.11 - Unauthenticated Privilege Escalation via Registration Role Encryption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75823"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-100143",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00146,
      "epss_percentile": 0.03269,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "FluentCart A New Era of eCommerce",
      "cwe": "CWE-287",
      "title": "FluentCart < 1.6.5 - Unauthenticated Guest Customer Account Takeover via Checkout Email",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100143"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-75824",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00146,
      "epss_percentile": 0.03269,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "User Frontend",
      "cwe": "CWE-284",
      "title": "WP User Frontend 2.5.8 - 4.3.11 - Unauthenticated Account Creation with Registration Disabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75824"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-97316",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.03141,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Broken Link Notifier",
      "cwe": "CWE-918",
      "title": "Broken Link Notifier 1.3.1 - 2.0.0 - Unauthenticated SSRF via Redirect Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97316"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-86789",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.03215,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Connections Business Directory",
      "cwe": "CWE-200",
      "title": "Connections Business Directory <= 10.4.67 - Unauthenticated Non-Public Directory Entry Disclosure via cn-api/v1 REST Routes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86789"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-94274",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.03215,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "YayReviews",
      "cwe": "CWE-200",
      "title": "YayReviews 1.0.4 - 1.4.0 - Unauthenticated Sensitive Data Disclosure via REST API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94274"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-96886",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.03215,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Course Booking System",
      "cwe": "CWE-200",
      "title": "Course Booking System < 7.0.9 - Unauthenticated Attendee PII Disclosure via CSV Export",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96886"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-103106",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00141,
      "epss_percentile": 0.02893,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pexip",
      "product": "Infinity",
      "cwe": "CWE-669",
      "title": "Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation within an internal Pexip Infinity service that allows an attacker with local access to escalate privileges to root. Exploitation requires an attacker to be able to run arbitrary code on a node by either achieving remote code execution via some other vulnerability or having administrative access to the operating system.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103106"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-93460",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.02712,
      "kev": false,
      "kev_due_at": null,
      "vendor": "baserCMS User Community",
      "product": "baserCMS",
      "cwe": "CWE-79",
      "title": "A stored cross-site scripting vulnerability via appended strings in email form fields exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93460"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-93464",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.02712,
      "kev": false,
      "kev_due_at": null,
      "vendor": "baserCMS User Community",
      "product": "baserCMS",
      "cwe": "CWE-79",
      "title": "A stored cross-site scripting vulnerability via custom content descriptions exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93464"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-91072",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.02737,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "EWWW Image Optimizer",
      "cwe": "CWE-73",
      "title": "EWWW Image Optimizer < 8.8.0 - Admin+ WebP File Rename and Deletion via Unrestricted Path in WebP Migration Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91072"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-90953",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.02737,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Image Optimizer",
      "cwe": "CWE-200",
      "title": "Image Optimizer by Elementor < 1.7.7 - Subscriber+ Attachment Metadata and Site Statistics Disclosure via Discarded REST Permission Callbacks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90953"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-88797",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00132,
      "epss_percentile": 0.02316,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Vayu X",
      "cwe": "CWE-284",
      "title": "Vayu X < 1.0.6 - Subscriber+ Arbitrary WordPress.org Plugin Installation and Activation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88797"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-85576",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.02315,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "All in One Files Upload",
      "cwe": "CWE-862",
      "title": "All in One Files Upload for WooCommerce < 2.0.17 - Subscriber+ Arbitrary Plugin Settings Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85576"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-89190",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.02316,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Robin Image Optimizer",
      "cwe": "CWE-284",
      "title": "Robin Image Optimizer < 2.0.8 - Subscriber+ Plugin Settings Disclosure via fy_ajax",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89190"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-94297",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00132,
      "epss_percentile": 0.02315,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Media Library Organizer",
      "cwe": "CWE-862",
      "title": "Media Library Organizer 2.0.4 - 2.1.3 - Contributor+ Arbitrary Taxonomy Term Creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94297"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-102508",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00124,
      "epss_percentile": 0.01827,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache PLC4X",
      "cwe": "CWE-295",
      "title": "Apache PLC4X: OPC UA secure channel: integrity bypass, unverifiable server certificate, and silent downgrade",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102508"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-81310",
      "cvss_base": 5.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00119,
      "epss_percentile": 0.01596,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PFU Limited",
      "product": "Image Scanner Driver for Linux (fi Series)",
      "cwe": "CWE-59",
      "title": "Image Scanner Driver for Linux contains a link following vulnerability. An attacker who can log in to a Linux system where the product is installed may overwrite arbitrary files by using a special method in advance.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81310"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-91832",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00106,
      "epss_percentile": 0.01018,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Mobile Menu",
      "cwe": "CWE-79",
      "title": "WP Mobile Menu 2.7.4 - 2.8.8 - Stored XSS via CSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91832"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-55107",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "elct9620",
      "product": "kobako",
      "cwe": "CWE-94",
      "title": "Kobako Vulnerable to Sandbox Escape: guest eval reaches host RCE via method_missing → public_send (any bound Service)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55107"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-76570",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomcode.com",
      "product": "JCTables extension for Joomla",
      "cwe": "CWE-89",
      "title": "Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and write queries in JCTables < 1.21.1",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76570"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-96349",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SiteSkite",
      "product": "SiteSkite",
      "cwe": "CWE-94",
      "title": "WordPress SiteSkite plugin <= 2.1.8 - Remote Code Execution (RCE) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96349"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-102427",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ordasoft.com",
      "product": "OrdaSoft Joomla CCK",
      "cwe": "CWE-434",
      "title": "Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102427"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-18782",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Trex Digital Smart Manufacturing Systems Inc.",
      "product": "Trex MES",
      "cwe": "CWE-89",
      "title": "SQL Injection in Trex Digital Manufacturing's Trex MES",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18782"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-55494",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Quenary",
      "product": "tugtainer",
      "cwe": "CWE-284",
      "title": "Tugtainer: Unauthenticated access to Tugtainer Agent Docker management APIs when AGENT_SECRET is unset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55494"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-82307",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dolusoft Software Technologies",
      "product": "SOPLOG",
      "cwe": "CWE-89",
      "title": "Multiple Vulnerabilities in Dolusoft Software's SOPLOG",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82307"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-88920",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache WSS4J",
      "cwe": "CWE-287",
      "title": "Apache WSS4J: SAML Sender-Vouches Authentication Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88920"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-96350",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Estatik",
      "product": "Estatik",
      "cwe": "CWE-266",
      "title": "WordPress Estatik plugin <= 4.3.5 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96350"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-97248",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Booking Activities Team",
      "product": "Booking Activities",
      "cwe": "CWE-502",
      "title": "WordPress Booking Activities plugin <= 1.18.7.1 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97248"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-97274",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "miniOrange",
      "product": "OAuth Single Sign On – SSO (OAuth Client)",
      "cwe": "CWE-290",
      "title": "WordPress OAuth Single Sign On – SSO (OAuth Client) plugin <= 7.1.2 - Bypass vulnerability vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97274"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-100512",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hook & Filter",
      "product": "Nested Pages",
      "cwe": "CWE-502",
      "title": "WordPress Nested Pages plugin <= 3.3.2 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100512"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-102115",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Core",
      "cwe": "CWE-640",
      "title": "Kiteworks Core Authentication Bypass in the Password Reset Workflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102115"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-55181",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Quenary",
      "product": "tugtainer",
      "cwe": "CWE-284",
      "title": "Tugtainer: OIDC login remains accessible when OIDC_ENABLED is false",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55181"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-93903",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "litespeedtech",
      "product": "LiteSpeed Web Server",
      "cwe": "CWE-174",
      "title": "LiteSpeed Web Server (LSWS) before 6.3.7 build 1 mishandles internal redirect URL validation in a certain \"corner case.\"",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93903"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-102149",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Email Protection Gateway",
      "cwe": "CWE-306",
      "title": "Kiteworks Email Protection Gateway Improper Access Control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102149"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-102489",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zammad GmbH",
      "product": "Zammad",
      "cwe": null,
      "title": "Undisclosed RCE in Zammad v6.3 and higher",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102489"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-102490",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zammad GmbH",
      "product": "Zammad",
      "cwe": null,
      "title": "Undisclosed LPE in Zammad v1.5.0 to v7.1.0-alpha",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102490"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-74864",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YunoHost-Apps",
      "product": "sogo_yhn",
      "cwe": "CWE-639",
      "title": "Authentication Bypass in sogo_yhn",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74864"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-96822",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hossni Mubarak",
      "product": "Books Gallery",
      "cwe": "CWE-89",
      "title": "WordPress Books Gallery plugin <= 4.8.3 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96822"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-102147",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Core",
      "cwe": "CWE-79",
      "title": "Kiteworks Core Administrative Account Takeover through Stored Cross-site Scripting (XSS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102147"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-103395",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ModelTC",
      "product": "LightLLM",
      "cwe": "CWE-502",
      "title": "LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Visual-Only RPyC Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103395"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-103470",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Internet2",
      "product": "Grouper",
      "cwe": "CWE-266",
      "title": "In Internet2 Grouper before 7.5.1 (in some configurations), a user who is allowed to create or edit rules in the User Interface can escalate privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103470"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-103475",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yii2-starter-kit",
      "product": "yii2-starter-kit",
      "cwe": "CWE-489",
      "title": "yii2-starter-kit through 4.2.0 Debug and Gii Module Exposure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103475"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-19445",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Python Software Foundation",
      "product": "CPython",
      "cwe": "CWE-416",
      "title": "Use-after-free of a server-side SSLContext when sni_callback switches contexts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19445"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-74865",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YunoHost-Apps",
      "product": "sogo_yhn",
      "cwe": "CWE-639",
      "title": "Authentication Bypass in sogo_yhn",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74865"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-101276",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "esnet",
      "product": "iperf3",
      "cwe": "CWE-416",
      "title": "iperf3 3.21 (esnet/iperf) contains a remote, unauthenticated heap use-after-free: the server's per-test watchdog server_timer_proc() frees streams without cancelling/joining their worker threads, so a blocked worker dereferences a freed iperf_stream; fixed in 3.22.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101276"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-101283",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "esnet",
      "product": "iperf3",
      "cwe": "CWE-122",
      "title": "iperf3 3.20–3.21 (esnet/iperf) has a pre-auth heap buffer overflow in decrypt_rsa_message(): a 256-byte RSA buffer is BIO_read with the attacker-controlled ciphertext length (guard warns only), so an unauthenticated client overflows the heap via an oversized authtoken; fixed in 3.22",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101283"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-102992",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "piscinajs",
      "product": "piscina",
      "cwe": "CWE-1321",
      "title": "piscina: Prototype-pollution gadget in ThreadPool.options allows RCE via execArgv / loadBalancer / env",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102992"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-103473",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "denoland",
      "product": "deno",
      "cwe": "CWE-78",
      "title": "Deno 2.7.0 through 2.9.7 Command Injection via node:child_process",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103473"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-103547",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenBSD",
      "product": "OpenBSD",
      "cwe": "CWE-863",
      "title": "In ldapd in OpenBSD 7.8 before errata 057 and 7.9 before errata 021, delegated BSD authentication results are correlated only by the LDAP child process client file descriptor and LDAP message ID. After a connection closes, a later connection that reuses the same file descriptor and message ID can receive the earlier authentication result. A remote attacker who can reach ldapd can complete a Bind as another identity. A missing connection can also cause a NULL pointer dereference. (ldapd is not enabled by default.)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103547"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-62308",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Quenary",
      "product": "tugtainer",
      "cwe": "CWE-918",
      "title": "Tugtainer: Authenticated SSRF via arbitrary notification URLs in test_notification endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62308"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-75969",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PTZOptics",
      "product": "Move 4K 12X",
      "cwe": "CWE-306",
      "title": "PTZOptics Missing Authentication in Firmware Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75969"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-87830",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache WSS4J",
      "cwe": "CWE-917",
      "title": "Apache WSS4J: Streaming WS-SecurityPolicy validation may skip element-protection checks.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87830"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-89238",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache WSS4J",
      "cwe": "CWE-345",
      "title": "Apache WSS4J: WSS4J EncryptedHeader child confusion causing wrong protected-header selection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89238"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-102095",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Email Protection Gateway",
      "cwe": "CWE-918",
      "title": "Kiteworks Email Protection Gateway server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102095"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-102102",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Email Protection Gateway",
      "cwe": "CWE-918",
      "title": "Kiteworks Email Protection Gateway server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102102"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-102103",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Email Protection Gateway",
      "cwe": "CWE-918",
      "title": "Kiteworks Email Protection Gateway server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102103"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-102104",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Email Protection Gateway",
      "cwe": "CWE-918",
      "title": "Kiteworks Email Protection Gateway server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102104"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-102105",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Email Protection Gateway",
      "cwe": "CWE-918",
      "title": "Kiteworks Email Protection Gateway server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102105"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-102106",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Email Protection Gateway",
      "cwe": "CWE-287",
      "title": "Kiteworks Email Protection Gateway improper authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102106"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-55176",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Soft-Machine-io",
      "product": "security",
      "cwe": "CWE-863",
      "title": "Soft Machine: Cross-tenant workspace API auth bypass via shared `CONTAINER_SHARED_SECRET` bearer token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55176"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-94389",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AcyMailing Newsletter Team",
      "product": "AcyMailing SMTP Newsletter",
      "cwe": "CWE-94",
      "title": "WordPress AcyMailing SMTP Newsletter plugin <= 11.0.5 - Remote Code Execution (RCE) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94389"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-100277",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-863",
      "title": "In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signature",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100277"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-18783",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Trex Digital Smart Manufacturing Systems Inc.",
      "product": "Trex MES",
      "cwe": "CWE-306",
      "title": "Missing Server-Side Authentication on REST API Endpoint in Trex Digital Manufacturing's Trex MES",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18783"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-94076",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SEO Squirrly",
      "product": "SEO Plugin by Squirrly SEO",
      "cwe": "CWE-502",
      "title": "WordPress SEO Plugin by Squirrly SEO plugin <= 14.2.5 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94076"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-94121",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "10Web",
      "product": "10Web Booster – Website speed optimization, Cache & Page Speed optimizer",
      "cwe": "CWE-502",
      "title": "WordPress 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin <= 2.33.6 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94121"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-94678",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mat Lipe",
      "product": "Go Live Update Urls",
      "cwe": "CWE-502",
      "title": "WordPress Go Live Update Urls plugin <= 7.0.8 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94678"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-94683",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Justin Nealey",
      "product": "DesignSetGo",
      "cwe": "CWE-502",
      "title": "WordPress DesignSetGo plugin <= 2.8.0 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94683"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-95531",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QuantumCloud",
      "product": "Conversational Forms for ChatBot",
      "cwe": "CWE-502",
      "title": "WordPress Conversational Forms for ChatBot plugin <= 1.5.0 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95531"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-96831",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themifyme",
      "product": "Themify Builder",
      "cwe": "CWE-502",
      "title": "WordPress Themify Builder plugin <= 7.8.1 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96831"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-96837",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Brainstorm Force",
      "product": "CartFlows",
      "cwe": "CWE-98",
      "title": "WordPress CartFlows plugin <= 3.2.0 - Remote Code Execution (RCE) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96837"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-96838",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YoOhw Studio",
      "product": "Blacklist Manager &#8211; WooCommerce Anti-Fraud, Blacklist &amp; Checkout Verification",
      "cwe": "CWE-352",
      "title": "WordPress Blacklist Manager &#8211; WooCommerce Anti-Fraud, Blacklist &amp; Checkout Verification plugin <= 2.3.1 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96838"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-97291",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Magazine3",
      "product": "Schema & Structured Data for WP & AMP",
      "cwe": "CWE-502",
      "title": "WordPress Schema & Structured Data for WP & AMP plugin <= 1.66 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97291"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-100253",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "TeamCity",
      "cwe": "CWE-184",
      "title": "In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 sandbox escape leading to code execution was possible via the versioned settings Kotlin DSL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100253"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-100254",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "TeamCity",
      "cwe": "CWE-78",
      "title": "In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 authenticated users could execute commands on Windows servers via CRLF injection in Pipeline Git connection settings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100254"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-102120",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Core",
      "cwe": "CWE-78",
      "title": "Kiteworks Core OS Command Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102120"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-102125",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Core",
      "cwe": "CWE-653",
      "title": "Kiteworks Core Sandbox Escape",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102125"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-102377",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "10Web",
      "product": "Photo Gallery by 10Web",
      "cwe": "CWE-502",
      "title": "WordPress Photo Gallery by 10Web plugin <= 1.8.46 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102377"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2023-54402",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "iDocView",
      "product": "iDocView",
      "cwe": "CWE-918",
      "title": "iDocView SSRF via /doc/upload Endpoint Hardcoded Token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-54402"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2023-54403",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Yonyou",
      "product": "U8 CRM",
      "cwe": "CWE-22",
      "title": "Yonyou U8 CRM Arbitrary File Read via getemaildata.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-54403"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2024-58387",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Inspur",
      "product": "Haiyue HCM Cloud",
      "cwe": "CWE-22",
      "title": "Inspur HCM Cloud Arbitrary File Read via file/download Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-58387"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-47097",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AJA Video Systems",
      "product": "HELO Plus",
      "cwe": "CWE-321",
      "title": "AJA HELO Plus < 2.1.7 Hardcoded AES Passphrase for Diagnostics Export Bundle",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47097"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-55094",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "taskcluster",
      "product": "taskcluster",
      "cwe": "CWE-20",
      "title": "Taskcluster: Unauthenticated remote code execution in `web-server` via GraphQL `filter` argument (sift `$where`)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55094"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-55224",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mineadmin",
      "product": "MineAdmin",
      "cwe": "CWE-22",
      "title": "MineAdmin: Path Traversal via Unsanitized identifier in Plugin Install/Uninstall",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55224"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-76992",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CODESYS",
      "product": "Development System 3",
      "cwe": "CWE-770",
      "title": "Uncontrolled Memory Allocation in CODESYS Gateway Client",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76992"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-101880",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw Windows Node",
      "cwe": "CWE-863",
      "title": "OpenClaw Windows Node before 2026.7.1 Authorization Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101880"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-101882",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw Windows Node",
      "cwe": "CWE-184",
      "title": "OpenClaw Windows Node before 2026.7.1 Remote Code Execution via system.execApprovals.set",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101882"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-102092",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Core",
      "cwe": "CWE-79",
      "title": "Kiteworks Core stored XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102092"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-102100",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Core",
      "cwe": "CWE-79",
      "title": "Kiteworks Core stored XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102100"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-102993",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "py-pdf",
      "product": "pypdf",
      "cwe": "CWE-400",
      "title": "pypdf: Possible large memory usage when retrieving Roman page labels",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102993"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-102994",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "py-pdf",
      "product": "pypdf",
      "cwe": "CWE-400",
      "title": "pypdf: Possible long runtimes/large memory usage when parsing indirect objects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102994"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-102995",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "py-pdf",
      "product": "pypdf",
      "cwe": "CWE-400",
      "title": "pypdf: Possible large memory usage for large /ToUnicode streams (Follow-up 2)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102995"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-102996",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "py-pdf",
      "product": "pypdf",
      "cwe": "CWE-400",
      "title": "pypdf: Possible large memory usage when parsing font data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102996"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-102997",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "py-pdf",
      "product": "pypdf",
      "cwe": "CWE-400",
      "title": "pypdf: Possible long runtimes for partially malformed FlateDecode streams (Follow-up)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102997"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-102998",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "py-pdf",
      "product": "pypdf",
      "cwe": "CWE-400",
      "title": "pypdf: Possible long runtimes when generating appearance streams",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102998"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-102999",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "py-pdf",
      "product": "pypdf",
      "cwe": "CWE-400",
      "title": "pypdf: Possible long runtimes with large amount of embedded files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102999"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-103000",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "py-pdf",
      "product": "pypdf",
      "cwe": "CWE-400",
      "title": "pypdf: Possible large memory usage when retrieving alphabetical page labels",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103000"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-103270",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ModelTC",
      "product": "LightLLM",
      "cwe": "CWE-306",
      "title": "LightLLM through 1.2.0 Missing Authentication on RL Control Routes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103270"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-103471",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Corvusoft",
      "product": "restbed",
      "cwe": "CWE-770",
      "title": "restbed through 5.0.0 Denial of Service via Unbounded Header Buffering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103471"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-103472",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Corvusoft",
      "product": "restbed",
      "cwe": "CWE-770",
      "title": "restbed through 5.0.0 WebSocket Memory Exhaustion via Unbounded Frame Buffering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103472"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-103474",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yii2-starter-kit",
      "product": "yii2-starter-kit",
      "cwe": "CWE-434",
      "title": "yii2-starter-kit through 4.2.0 Unrestricted File Upload RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103474"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-103591",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AsyncFuncAI",
      "product": "deepwiki-open",
      "cwe": "CWE-73",
      "title": "DeepWiki-Open through commit d92819a Unauthenticated Arbitrary File Read via /codemap/file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103591"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-102121",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Secure Data Forms",
      "cwe": "CWE-200",
      "title": "Kiteworks Secure Data Forms Exposure of Sensitive Information to an Unauthorized Actor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102121"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-103239",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-284",
      "title": "MISP Tag Collection Save Allows Privilege Escalation via Sibling Model Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103239"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-103398",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Liquid-co",
      "product": "OpenSave",
      "cwe": "CWE-73",
      "title": "OpenSave through 2.4.0 Arbitrary File Read and Write via Peer-Controlled Save Path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103398"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-10739",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cato Networks",
      "product": "SDP Client",
      "cwe": "CWE-23",
      "title": "Cato Networks SDP Client for Windows is vulnerable to Local Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10739"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-94115",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fatcatapps",
      "product": "Easy Pricing Tables",
      "cwe": "CWE-89",
      "title": "WordPress Easy Pricing Tables plugin <= 4.1.2 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94115"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-94177",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ruben Garcia",
      "product": "GamiPress",
      "cwe": "CWE-89",
      "title": "WordPress GamiPress plugin <= 8.0.2 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94177"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-97287",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nexcess",
      "product": "Event Tickets",
      "cwe": "CWE-89",
      "title": "WordPress Event Tickets plugin <= 5.29.5 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97287"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-97293",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "David Lingren",
      "product": "Media LIbrary Assistant",
      "cwe": "CWE-89",
      "title": "WordPress Media LIbrary Assistant plugin <= 3.41 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97293"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-101885",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zeroclaw-labs",
      "product": "ZeroClaw",
      "cwe": "CWE-22",
      "title": "ZeroClaw before 0.8.5 Path Traversal via Plugin Manifest wasm_path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101885"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-46711",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Soft-Machine-io",
      "product": "security",
      "cwe": "CWE-306",
      "title": "Soft Machine: Unauthenticated workspace API exposes arbitrary file read & directory exfiltration to any peer on the Fly private network",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46711"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-103321",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-20",
      "title": "MISP Stored Cross-Site Scripting (XSS) via Unvalidated Event Graph Preview Image",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103321"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-93621",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Passionate Programmer Peter",
      "product": "WP Data Access",
      "cwe": "CWE-89",
      "title": "WordPress WP Data Access plugin <= 5.5.84 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93621"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-96817",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MakeCommerce.net",
      "product": "MakeCommerce for WooCommerce",
      "cwe": "CWE-862",
      "title": "WordPress MakeCommerce for WooCommerce plugin <= 4.1.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96817"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-100273",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-863",
      "title": "In JetBrains YouTrack before 2026.2.19197 authorisation bypass in the scripts debugger allowed arbitrary code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100273"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-102984",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "withastro",
      "product": "astro",
      "cwe": "CWE-248",
      "title": "Astro: Malformed port in the Host header can crash the Node adapter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102984"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-102990",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patrickjuchli",
      "product": "basic-ftp",
      "cwe": "CWE-1333",
      "title": "basic-ftp: Quadratic-time CPU denial of service in Client.list() Unix directory-listing parser (RE_LINE backtracking)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102990"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-51568",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "modelscope Agentscope v1.0.18-v1.0.0 is vulnerable to Path Traversal in write_text_file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51568"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-51570",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "modelscope Agentscope v1.0.0-v1.0.8 is vulnerable to Path Traversal in insert_text_file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51570"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-87004",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Quenary",
      "product": "tugtainer",
      "cwe": "CWE-347",
      "title": "Tugtainer: OIDC id_token claims accepted without signature/audience/expiry verification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87004"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-100255",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "TeamCity",
      "cwe": "CWE-1289",
      "title": "In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password reset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100255"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-102101",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Core",
      "cwe": "CWE-502",
      "title": "Kiteworks Core deserialization of untrusted data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102101"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-102126",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Core",
      "cwe": "CWE-79",
      "title": "Kiteworks Core Stored Cross-site Scripting (XSS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102126"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-103432",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "apcupsd",
      "product": "apcupsd",
      "cwe": "CWE-121",
      "title": "apcupsd through 3.14.14 has an sscanf stack-based buffer overflow in getupsvar() in src/cgi/upsfetch.c (used by upsstats.cgi, multimon.cgi, and upsfstats.cgi), a related issue to CVE-2026-15544.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103432"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-47489",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-281",
      "title": "NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where permissions on read-only memory might not be preserved. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47489"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-47491",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-404",
      "title": "NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user can cause improper release of memory resources, leaving a mapping accessible after the underlying memory is reused. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47491"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-47493",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Virtual GPU Manager",
      "cwe": "CWE-862",
      "title": "NVIDIA vGPU software for Windows and Linux contains a vulnerability in the GPU kernel driver where a guest may access privileged host GPU resources for which it is not authorized. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47493"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-47494",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-134",
      "title": "NVIDIA GPU Display Driver for Linux contains a vulnerability where a user might be able to cause a format string issue. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47494"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-47495",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Virtual GPU Manager",
      "cwe": "CWE-787",
      "title": "NVIDIA vGPU Virtual GPU Manager for Windows and Linux contains a vulnerability in the kernel mode layer where a user could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47495"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-47497",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Virtual GPU Manager",
      "cwe": "CWE-367",
      "title": "NVIDIA Virtual GPU Manager contains a vulnerability in the GPU System Processor (GSP) tracing component where a guest VM user may cause improper access by sending crafted data through a shared buffer. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47497"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-47498",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Virtual GPU Manager",
      "cwe": "CWE-787",
      "title": "NVIDIA vGPU Manager contains a vulnerability in the GPU System Processor (GSP) plugin where a guest VM user may cause an out-of-bounds write by sending a specially crafted RPC message. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47498"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-47499",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Virtual GPU Manager",
      "cwe": "CWE-125",
      "title": "NVIDIA vGPU Virtual GPU Manager for Windows and Linux contains a vulnerability in the kernel mode layer where a guest could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47499"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-47500",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-416",
      "title": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where improper cleanup of reference counts during error paths could lead to a use-after-free condition. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47500"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-47501",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-787",
      "title": "NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a user could cause an out-of-bounds write by supplying mismatched memory buffers during event buffer setup. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47501"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-47502",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-190",
      "title": "NVIDIA vGPU Virtual GPU Manager for Windows and Linux contains a vulnerability in the kernel mode layer, where a guest user could cause an integer overflow leading to memory corruption. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47502"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-47503",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Virtual GPU Manager",
      "cwe": "CWE-787",
      "title": "NVIDIA GPU Display Driver for Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a guest VM user may cause an out-of-bounds write by sending a crafted RPC message with invalid performance state list size parameters. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47503"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-47504",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-843",
      "title": "NVIDIA Linux GPU Display Driver contains a vulnerability in the NGX updater where an outdated embedded cryptographic library is susceptible to type confusion. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, or data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47504"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-47505",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-416",
      "title": "NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer where an attacker could cause a use-after-free. A successful exploit of this vulnerability might lead to code execution, denial of service, or escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47505"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-47507",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-129",
      "title": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an out-of-bounds array access. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47507"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-47508",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-681",
      "title": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an incorrect conversion between numeric types. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47508"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-47510",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-190",
      "title": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an integer overflow leading to an out-of-bounds write to GPU memory. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47510"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-47511",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-787",
      "title": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47511"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-47512",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-125",
      "title": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an out-of-bounds read leading to kernel information disclosure. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47512"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-47513",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-125",
      "title": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an out-of-bounds read from kernel heap memory. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47513"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-47514",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-200",
      "title": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause exposure of kernel stack contents including return addresses and pointers. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47514"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-47516",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-416",
      "title": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where an unprivileged user could cause a use-after-free. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47516"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-47519",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Guest driver",
      "cwe": "CWE-125",
      "title": "NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47519"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-47520",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Guest driver",
      "cwe": "CWE-125",
      "title": "NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47520"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-47521",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Virtual GPU Manager",
      "cwe": "CWE-125",
      "title": "NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47521"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-47523",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-787",
      "title": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47523"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-47528",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-824",
      "title": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the firmware where an attacker could cause an access of an uninitialized pointer. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47528"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-47530",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-787",
      "title": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47530"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-47535",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Virtual GPU Manager",
      "cwe": "CWE-125",
      "title": "NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the firmware where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47535"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-47536",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Virtual GPU Manager",
      "cwe": "CWE-125",
      "title": "NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47536"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-47540",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-191",
      "title": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an integer underflow. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47540"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-47541",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Virtual GPU Manager",
      "cwe": "CWE-787",
      "title": "NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47541"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-47545",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-125",
      "title": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47545"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-47548",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-787",
      "title": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47548"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-47550",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-119",
      "title": "NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer where an unprivileged local user can supply an untrusted pointer that the driver dereferences without validation. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47550"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-47551",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-416",
      "title": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where a user could cause a use-after-free. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47551"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-47552",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-862",
      "title": "NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user could bypass an authorization check and modify privileged configuration. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47552"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-47553",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-787",
      "title": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an unprivileged user could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47553"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-47556",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-190",
      "title": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an unprivileged user could cause an integer overflow that leads to an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47556"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-47558",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-415",
      "title": "NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user could cause a double-free of imported memory state. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47558"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-47559",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-862",
      "title": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could access memory belonging to another user's process. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47559"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-47560",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-416",
      "title": "NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user could cause a use-after-free. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47560"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-47561",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-787",
      "title": "NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where the size of an ioctl input buffer is not validated, allowing an unprivileged caller to trigger an out-of-bounds write in kernel memory. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47561"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-47563",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-476",
      "title": "NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a user could cause a NULL pointer dereference. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47563"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-47569",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-843",
      "title": "NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a user could cause a type confusion via a handle recycle race. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47569"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-47570",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-427",
      "title": "NVIDIA GPU Display Driver for Windows contains a vulnerability in the CUDA driver where an attacker could cause a library to be loaded from an uncontrolled search path. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, data tampering, and denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47570"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-47571",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-863",
      "title": "NVIDIA GPU Display Driver for Windows contains a vulnerability in kernel-mode escape handling where an attacker with local access could bypass an authorization check that is intended to restrict certain operations based on client execution context. A successful exploit of this vulnerability might lead to escalation of privilege, information disclosure, data tampering, denial of service, or code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47571"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-47572",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-843",
      "title": "NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a user could cause type confusion. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47572"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-47573",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-787",
      "title": "NVIDIA NVAPI for Windows contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47573"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-47574",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Virtual GPU Manager",
      "cwe": "CWE-669",
      "title": "NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability where an attacker could cause incorrect resource transfer between spheres. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47574"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-47575",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-787",
      "title": "NVIDIA GPU Display Driver for Windows contains a vulnerability in the display driver DIAG escape handler where a local unprivileged attacker may cause an integer overflow and out-of-bounds write. A successful exploit of this vulnerability might lead to denial of service, and code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47575"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-47577",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-190",
      "title": "NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where an attacker could cause an incorrect comparison. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47577"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-47578",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-131",
      "title": "NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer where an attacker could cause an incorrect buffer size calculation. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47578"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-47579",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-416",
      "title": "The NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode driver through which a user might trigger a use-after-free condition. Successful exploitation of this issue could lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47579"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-47583",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-843",
      "title": "NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where an attacker could cause type confusion. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47583"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-47585",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-191",
      "title": "NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where an attacker could cause an integer underflow. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47585"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-47587",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "RTX, Quadro, NVS",
      "cwe": "CWE-416",
      "title": "NVIDIA GPU Display Driver for Linux contains a vulnerability where an unprivileged user could cause a use-after-free. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47587"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-47588",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "RTX, Quadro, NVS",
      "cwe": "CWE-416",
      "title": "NVIDIA GPU Display Driver for Linux contains a vulnerability where an unprivileged user could cause a use-after-free condition by issuing a sequence of driver commands. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47588"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-47589",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-416",
      "title": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where an unprivileged user may cause a use-after-free condition by issuing a sequence of driver commands. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47589"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-47590",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-416",
      "title": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where an unprivileged user may cause a use-after-free condition by issuing a sequence of driver commands. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47590"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-47591",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-863",
      "title": "NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user could bypass read-only memory protection due to incorrect authorization, enabling write access to memory marked read-only. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47591"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-47592",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-125",
      "title": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an unprivileged user could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47592"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-47593",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-121",
      "title": "NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer where an unprivileged user can cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, and denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47593"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-47594",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-416",
      "title": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where an unprivileged user may cause a use-after-free condition by issuing a sequence of driver commands. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, data tampering, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47594"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-47595",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-281",
      "title": "NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user can write to read-only memory because the memory's permissions are not preserved. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47595"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-47597",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-416",
      "title": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the open-source kernel module Resource Server where an unprivileged local user could cause a use-after-free through a missing self-reference guard in the map cleanup path. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47597"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-47599",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-281",
      "title": "NVIDIA GPU Display Driver for Linux contains a vulnerability in the open-source kernel module where an unprivileged local user could cause improper preservation of memory access permissions during DMA mapping. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47599"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-47600",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-908",
      "title": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an error-handling path could operate on an improperly initialized resource. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47600"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-47601",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-787",
      "title": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the open-source kernel module DMA-BUF import path where an unprivileged local user could cause improper preservation of memory access permissions when importing a read-only buffer from another device's DMA-BUF exporter. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47601"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-53605",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pollen-robotics",
      "product": "reachy-mini-os",
      "cwe": "CWE-250",
      "title": "Reachy Mini Wireless: Local Privilege Escalation via Unrestricted sudo systemctl Grant",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53605"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-62146",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift Container Platform 4",
      "cwe": "CWE-501",
      "title": "Cri-o: cri-o: sandbox state poisoning via pod annotations may expose runtime socket",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62146"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-100256",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "IntelliJ IDEA",
      "cwe": "CWE-829",
      "title": "In JetBrains IntelliJ IDEA before 2026.2.3 rCE via Structural Search script constraints was possible in untrusted projects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100256"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-102112",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Core",
      "cwe": "CWE-78",
      "title": "Kiteworks Core Local Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102112"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-102113",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Core",
      "cwe": "CWE-59",
      "title": "Kiteworks Core Local Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102113"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-102118",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Core",
      "cwe": "CWE-59",
      "title": "Kiteworks Core before version 9.5.0 is vulnerable to Local Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102118"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-47576",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-125",
      "title": "NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module through which an attacker might initiate an out-of-bounds read. Successful exploitation of this issue could lead to denial of service and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47576"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-100266",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "Hub",
      "cwe": "CWE-862",
      "title": "In JetBrains Hub before 2026.2.52366 missing authorisation allowed authenticated users to send arbitrary emails from the server's trusted address",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100266"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-100268",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-639",
      "title": "In JetBrains YouTrack before 2026.2.19197 project administrators could read comments from other projects via notification templates",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100268"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-101884",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw Windows Node",
      "cwe": "CWE-184",
      "title": "OpenClaw Windows Node before 2026.7.1 Remote Code Execution via Environment Override",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101884"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-19553",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Python Software Foundation",
      "product": "CPython",
      "cwe": "CWE-297",
      "title": "SSLContext.wrap_bio() missing validation of server_hostname parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19553"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-55177",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dfpc-coe",
      "product": "CloudTAK",
      "cwe": "CWE-918",
      "title": "CloudTAK: Authenticated full-read SSRF in /api/esri* routes — user-controlled URL fetched with no IP-classification guard",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55177"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-62085",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Melapress",
      "product": "WP Activity Log",
      "cwe": "CWE-89",
      "title": "WordPress WP Activity Log plugin <= 5.6.6 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62085"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-62097",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPTasty",
      "product": "Business Directory",
      "cwe": "CWE-89",
      "title": "WordPress Business Directory plugin <= 6.4.27 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62097"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-94082",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fatcatapps",
      "product": "Quiz Cat",
      "cwe": "CWE-89",
      "title": "WordPress Quiz Cat plugin <= 3.1.1 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94082"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-96345",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Estatik",
      "product": "Estatik",
      "cwe": "CWE-89",
      "title": "WordPress Estatik plugin <= 4.3.5 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96345"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-96346",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "weDevs",
      "product": "WP ERP",
      "cwe": "CWE-89",
      "title": "WordPress WP ERP plugin <= 1.17.9 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96346"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-96827",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Melapress",
      "product": "Admin Notices Manager",
      "cwe": "CWE-89",
      "title": "WordPress Admin Notices Manager plugin <= 1.6.0 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96827"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-96828",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Vidish",
      "product": "Category Discount Woocommerce",
      "cwe": "CWE-89",
      "title": "WordPress Category Discount Woocommerce plugin <= 5.18 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96828"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-100262",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-863",
      "title": "In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed users with read-only project access to overwrite project notification templates",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100262"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-85532",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache WSS4J",
      "cwe": "CWE-20",
      "title": "Apache WSS4J: Insufficient Validation of Derived-Key Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85532"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-92121",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache WSS4J",
      "cwe": "CWE-693",
      "title": "Apache WSS4J: WS-SecurityPolicy signature checks skipped in the streaming code after an STR-Transform reference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92121"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-94120",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GravityKit",
      "product": "GravityExport Lite for Gravity Forms",
      "cwe": "CWE-862",
      "title": "WordPress GravityExport Lite for Gravity Forms plugin <= 2.7.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94120"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-94123",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Syed Balkhi",
      "product": "NextGEN Gallery",
      "cwe": "CWE-22",
      "title": "WordPress NextGEN Gallery plugin <= 4.5.0 - Arbitrary File Download vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94123"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-94178",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Javier Carazo",
      "product": "Import and export users and customers",
      "cwe": "CWE-266",
      "title": "WordPress Import and export users and customers plugin <= 2.5.2 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94178"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-95587",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hostinger",
      "product": "Hostinger Migrator",
      "cwe": "CWE-862",
      "title": "WordPress Hostinger Migrator plugin <= 1.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95587"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-95616",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache WSS4J",
      "cwe": "CWE-190",
      "title": "Apache WSS4J: Unauthenticated denial of service via integer overflow in DER parsing of X.509 certificate extensions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95616"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-96348",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bookly",
      "product": "Bookly",
      "cwe": "CWE-862",
      "title": "WordPress Bookly plugin <= 28.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96348"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-96818",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mra13 / Team Tips and Tricks HQ",
      "product": "WP Express Checkout (Accept PayPal Payments)",
      "cwe": "CWE-862",
      "title": "WordPress WP Express Checkout (Accept PayPal Payments) plugin <= 2.4.9 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96818"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-96823",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CusRev",
      "product": "Customer Reviews for WooCommerce",
      "cwe": "CWE-862",
      "title": "WordPress Customer Reviews for WooCommerce plugin <= 5.120.0 - Arbitrary Content Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96823"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-97197",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebToffee",
      "product": "WordPress Backup & Migration",
      "cwe": "CWE-862",
      "title": "WordPress WordPress Backup & Migration plugin <= 1.6.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97197"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-97240",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Esteban",
      "product": "StifLi Backup Tools",
      "cwe": "CWE-201",
      "title": "WordPress StifLi Backup Tools plugin <= 2.2.7 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97240"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-97241",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PrecisionWP",
      "product": "BackupEase",
      "cwe": "CWE-201",
      "title": "WordPress BackupEase plugin <= 2.2.2 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97241"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-97244",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPFunnels",
      "product": "Creator LMS",
      "cwe": "CWE-35",
      "title": "WordPress Creator LMS plugin <= 1.2.19 - Path Traversal vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97244"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-102091",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Secure Data Forms",
      "cwe": "CWE-918",
      "title": "Kiteworks Secure Data Forms server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102091"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-102128",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Email Protection Gateway",
      "cwe": "CWE-287",
      "title": "Kiteworks Email Protection Gateway Improper Authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102128"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-102143",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Email Protection Gateway",
      "cwe": "CWE-306",
      "title": "Kiteworks Email Protection Gateway Unrestricted Upload of File with Dangerous Type",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102143"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-102717",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "NetX Duo",
      "cwe": "CWE-125",
      "title": "MQTT WebSocket setter ABI mismatch may disclose memory or cause a crash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102717"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-102123",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Core",
      "cwe": "CWE-22",
      "title": "Kiteworks Core Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102123"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-103446",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Wikimedia Foundation",
      "product": "MediaWiki WikiLambda extension",
      "cwe": "CWE-639",
      "title": "WikiLambda exposes anonymous execution of unsaved Abstract Wikipedia fragments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103446"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2026-47496",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Virtual GPU Manager",
      "cwe": "CWE-787",
      "title": "NVIDIA GPU Display Driver for Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin) where a guest VM user may cause an out-of-bounds write by sending a specially crafted RPC call to the host. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, and denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47496"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-47580",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-862",
      "title": "NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where an attacker could cause a missing authorization issue. A successful exploit of this vulnerability might lead to information disclosure and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47580"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-101295",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Assisted Installer for Red Hat OpenShift Container Platform 2",
      "cwe": "CWE-22",
      "title": "Oc-mirror: oc-mirror: path traversal / arbitrary file write in operator catalog image extraction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101295"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-93624",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "codepeople",
      "product": "Music Player for WooCommerce",
      "cwe": "CWE-502",
      "title": "WordPress Music Player for WooCommerce plugin <= 1.9.1 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93624"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-93651",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dotstore",
      "product": "Minimum and Maximum Quantity for WooCommerce",
      "cwe": "CWE-502",
      "title": "WordPress Minimum and Maximum Quantity for WooCommerce plugin <= 2.1.2 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93651"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-93771",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPFactory",
      "product": "Cost of Goods for WooCommerce",
      "cwe": "CWE-502",
      "title": "WordPress Cost of Goods for WooCommerce plugin <= 3.5.2 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93771"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2026-94122",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "A WP Life",
      "product": "Responsive Slider Gallery",
      "cwe": "CWE-502",
      "title": "WordPress Responsive Slider Gallery plugin <= 1.5.5 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94122"
    },
    {
      "rank": 354,
      "cve_id": "CVE-2026-94677",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nexcess",
      "product": "Kadence WooCommerce Email Designer",
      "cwe": "CWE-502",
      "title": "WordPress Kadence WooCommerce Email Designer plugin <= 1.5.19.1 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94677"
    },
    {
      "rank": 355,
      "cve_id": "CVE-2026-96343",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "weDevs",
      "product": "WP ERP",
      "cwe": "CWE-502",
      "title": "WordPress WP ERP plugin <= 1.17.9 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96343"
    },
    {
      "rank": 356,
      "cve_id": "CVE-2026-96344",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "impleCode",
      "product": "eCommerce Product Catalog",
      "cwe": "CWE-502",
      "title": "WordPress eCommerce Product Catalog plugin <= 3.6.0 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96344"
    },
    {
      "rank": 357,
      "cve_id": "CVE-2026-96815",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "appsbd",
      "product": "Vitepos",
      "cwe": "CWE-266",
      "title": "WordPress Vitepos plugin <= 3.5.0 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96815"
    },
    {
      "rank": 358,
      "cve_id": "CVE-2026-96832",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "keywordrush",
      "product": "Content Egg",
      "cwe": "CWE-502",
      "title": "WordPress Content Egg plugin <= 6.3.1 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96832"
    },
    {
      "rank": 359,
      "cve_id": "CVE-2026-96833",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themefic",
      "product": "Ultimate Addons for Contact Form 7",
      "cwe": "CWE-502",
      "title": "WordPress Ultimate Addons for Contact Form 7 plugin <= 3.5.51 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96833"
    },
    {
      "rank": 360,
      "cve_id": "CVE-2026-97245",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SureCart",
      "product": "SureCart",
      "cwe": "CWE-266",
      "title": "WordPress SureCart plugin <= 4.7.2 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97245"
    },
    {
      "rank": 361,
      "cve_id": "CVE-2026-97256",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Greg – SiteOrigin",
      "product": "Page Builder by SiteOrigin",
      "cwe": "CWE-502",
      "title": "WordPress Page Builder by SiteOrigin plugin <= 2.36.0 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97256"
    },
    {
      "rank": 362,
      "cve_id": "CVE-2026-102089",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Email Protection Gateway",
      "cwe": "CWE-22",
      "title": "Kiteworks Email Protection Gateway path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102089"
    },
    {
      "rank": 363,
      "cve_id": "CVE-2026-102093",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Core",
      "cwe": "CWE-269",
      "title": "Kiteworks Core improper privilege management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102093"
    },
    {
      "rank": 364,
      "cve_id": "CVE-2026-102094",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Email Protection Gateway",
      "cwe": "CWE-470",
      "title": "Kiteworks Email Protection Gateway unsafe reflection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102094"
    },
    {
      "rank": 365,
      "cve_id": "CVE-2026-102096",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Core",
      "cwe": "CWE-78",
      "title": "Kiteworks Core OS command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102096"
    },
    {
      "rank": 366,
      "cve_id": "CVE-2026-102097",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Email Protection Gateway",
      "cwe": "CWE-22",
      "title": "Kiteworks Email Protection Gateway remote code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102097"
    },
    {
      "rank": 367,
      "cve_id": "CVE-2026-102098",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Core",
      "cwe": "CWE-89",
      "title": "Kiteworks Core SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102098"
    },
    {
      "rank": 368,
      "cve_id": "CVE-2026-102099",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Core",
      "cwe": "CWE-22",
      "title": "Kiteworks Core arbitrary file write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102099"
    },
    {
      "rank": 369,
      "cve_id": "CVE-2026-102108",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Email Protection Gateway",
      "cwe": "CWE-502",
      "title": "Kiteworks Email Protection Gateway deserialization of untrusted data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102108"
    },
    {
      "rank": 370,
      "cve_id": "CVE-2026-102114",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Core",
      "cwe": "CWE-78",
      "title": "Kiteworks Core OS Command Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102114"
    },
    {
      "rank": 371,
      "cve_id": "CVE-2026-102116",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Email Protection Gateway",
      "cwe": "CWE-22",
      "title": "Kiteworks Email Protection Gateway Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102116"
    },
    {
      "rank": 372,
      "cve_id": "CVE-2026-102117",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Core",
      "cwe": "CWE-807",
      "title": "Kiteworks Core Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102117"
    },
    {
      "rank": 373,
      "cve_id": "CVE-2026-102119",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Email Protection Gateway",
      "cwe": "CWE-22",
      "title": "Kiteworks Email Protection Gateway Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102119"
    },
    {
      "rank": 374,
      "cve_id": "CVE-2026-102129",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Core",
      "cwe": "CWE-266",
      "title": "Kiteworks Core Incorrect Privilege Assignment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102129"
    },
    {
      "rank": 375,
      "cve_id": "CVE-2026-102130",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Email Protection Gateway",
      "cwe": "CWE-94",
      "title": "Kiteworks Email Protection Gateway Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102130"
    },
    {
      "rank": 376,
      "cve_id": "CVE-2026-102131",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Email Protection Gateway",
      "cwe": "CWE-94",
      "title": "Kiteworks Email Protection Gateway Improper Handling of Case Sensitivity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102131"
    },
    {
      "rank": 377,
      "cve_id": "CVE-2026-102132",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Core",
      "cwe": "CWE-284",
      "title": "Kiteworks Core Privilege Escalation through Improper Access Control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102132"
    },
    {
      "rank": 378,
      "cve_id": "CVE-2026-102142",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Core",
      "cwe": "CWE-1336",
      "title": "Kiteworks Core Remote Code Execution through Server-Side Template Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102142"
    },
    {
      "rank": 379,
      "cve_id": "CVE-2026-102150",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Secure Data Forms",
      "cwe": "CWE-306",
      "title": "Kiteworks Secure Data Forms Missing Authentication for Critical Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102150"
    },
    {
      "rank": 380,
      "cve_id": "CVE-2026-102392",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeHigh",
      "product": "Extra Product Options For WooCommerce | Custom Product Addons and Fields",
      "cwe": "CWE-502",
      "title": "WordPress Extra Product Options For WooCommerce | Custom Product Addons and Fields plugin <= 3.3.8 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102392"
    },
    {
      "rank": 381,
      "cve_id": "CVE-2026-103441",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Wikimedia Foundation",
      "product": "MediaWiki Wikibase extension",
      "cwe": "CWE-502",
      "title": "Unauthenticated arbitrary file deletion through Wikibase serialized entity parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103441"
    },
    {
      "rank": 382,
      "cve_id": "CVE-2026-103442",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Wikimedia Foundation",
      "product": "MediaWiki CentralAuth extension",
      "cwe": "CWE-15",
      "title": "MergeAccount PHP object injection via session-key substitution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103442"
    },
    {
      "rank": 383,
      "cve_id": "CVE-2026-27371",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPFunnels",
      "product": "WPFunnels",
      "cwe": "CWE-79",
      "title": "WordPress WPFunnels plugin <= 3.13.1 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27371"
    },
    {
      "rank": 384,
      "cve_id": "CVE-2026-47554",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-347",
      "title": "NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where improper verification of cryptographic signatures may cause signature verification to be bypassed under memory pressure. A successful exploit of this vulnerability might lead to denial of service and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47554"
    },
    {
      "rank": 385,
      "cve_id": "CVE-2026-47602",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-119",
      "title": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode driver where a local user can cause the driver to dereference an untrusted pointer. A successful exploit of this vulnerability might lead to denial of service and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47602"
    },
    {
      "rank": 386,
      "cve_id": "CVE-2026-93512",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ilGhera",
      "product": "JW Player for WordPress",
      "cwe": "CWE-79",
      "title": "WordPress JW Player for WordPress plugin <= 2.3.11 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93512"
    },
    {
      "rank": 387,
      "cve_id": "CVE-2026-93514",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rainafarai",
      "product": "Notification for Telegram",
      "cwe": "CWE-79",
      "title": "WordPress Notification for Telegram plugin <= 3.5.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93514"
    },
    {
      "rank": 388,
      "cve_id": "CVE-2026-93770",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VeronaLabs",
      "product": "WP Statistics",
      "cwe": "CWE-79",
      "title": "WordPress WP Statistics plugin <= 14.16.13 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93770"
    },
    {
      "rank": 389,
      "cve_id": "CVE-2026-94078",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gemini Labs",
      "product": "Site Reviews",
      "cwe": "CWE-79",
      "title": "WordPress Site Reviews plugin <= 8.3.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94078"
    },
    {
      "rank": 390,
      "cve_id": "CVE-2026-94081",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lukeseager",
      "product": "WordPress Persistent Login",
      "cwe": "CWE-79",
      "title": "WordPress WordPress Persistent Login plugin <= 3.1.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94081"
    },
    {
      "rank": 391,
      "cve_id": "CVE-2026-94171",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VillaTheme",
      "product": "CURCY",
      "cwe": "CWE-79",
      "title": "WordPress CURCY plugin <= 2.2.16 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94171"
    },
    {
      "rank": 392,
      "cve_id": "CVE-2026-94499",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpWax",
      "product": "FormGent",
      "cwe": "CWE-862",
      "title": "WordPress FormGent plugin <= 1.12.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94499"
    },
    {
      "rank": 393,
      "cve_id": "CVE-2026-96351",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RadiusTheme",
      "product": "Classified Listing",
      "cwe": "CWE-79",
      "title": "WordPress Classified Listing plugin <= 6.1.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96351"
    },
    {
      "rank": 394,
      "cve_id": "CVE-2026-96352",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YITHEMES",
      "product": "YITH WooCommerce Ajax Search",
      "cwe": "CWE-79",
      "title": "WordPress YITH WooCommerce Ajax Search plugin <= 2.28.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96352"
    },
    {
      "rank": 395,
      "cve_id": "CVE-2026-96814",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Titan Labs",
      "product": "WooCommerce Product Table Lite",
      "cwe": "CWE-79",
      "title": "WordPress WooCommerce Product Table Lite plugin <= 5.6.7 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96814"
    },
    {
      "rank": 396,
      "cve_id": "CVE-2026-96816",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vendidero",
      "product": "Trusted Shops Easy Integration for WooCommerce",
      "cwe": "CWE-79",
      "title": "WordPress Trusted Shops Easy Integration for WooCommerce plugin <= 2.0.6 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96816"
    },
    {
      "rank": 397,
      "cve_id": "CVE-2026-96819",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bobbingwide",
      "product": "oik",
      "cwe": "CWE-79",
      "title": "WordPress oik plugin <= 4.15.4 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96819"
    },
    {
      "rank": 398,
      "cve_id": "CVE-2026-96820",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "awesomesupport",
      "product": "Awesome Support",
      "cwe": "CWE-79",
      "title": "WordPress Awesome Support plugin <= 6.3.9 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96820"
    },
    {
      "rank": 399,
      "cve_id": "CVE-2026-96830",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nexcess",
      "product": "GiveWP",
      "cwe": "CWE-79",
      "title": "WordPress GiveWP plugin <= 4.16.9 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96830"
    },
    {
      "rank": 400,
      "cve_id": "CVE-2026-96836",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Morteza Geransayeh",
      "product": "Parsi Date",
      "cwe": "CWE-79",
      "title": "WordPress Parsi Date plugin <= 6.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96836"
    },
    {
      "rank": 401,
      "cve_id": "CVE-2026-97065",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Happyforms",
      "product": "Happyforms",
      "cwe": "CWE-79",
      "title": "WordPress Happyforms plugin <= 1.26.15 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97065"
    },
    {
      "rank": 402,
      "cve_id": "CVE-2026-97077",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spacetime",
      "product": "Ad Inserter",
      "cwe": "CWE-79",
      "title": "WordPress Ad Inserter plugin <= 2.8.18 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97077"
    },
    {
      "rank": 403,
      "cve_id": "CVE-2026-97235",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeRex",
      "product": "ThemeREX Addons",
      "cwe": "CWE-79",
      "title": "WordPress ThemeREX Addons plugin < 2.45.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97235"
    },
    {
      "rank": 404,
      "cve_id": "CVE-2026-97237",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Crocoblock. Jetimpex Inc.",
      "product": "JetEngine",
      "cwe": "CWE-79",
      "title": "WordPress JetEngine plugin <= 3.8.14.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97237"
    },
    {
      "rank": 405,
      "cve_id": "CVE-2026-97250",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dylan Kuhn",
      "product": "Geo Mashup",
      "cwe": "CWE-79",
      "title": "WordPress Geo Mashup plugin <= 1.13.21 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97250"
    },
    {
      "rank": 406,
      "cve_id": "CVE-2026-97253",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kreatura",
      "product": "LayerSlider",
      "cwe": "CWE-79",
      "title": "WordPress LayerSlider plugin <= 8.4.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97253"
    },
    {
      "rank": 407,
      "cve_id": "CVE-2026-97271",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPFunnels",
      "product": "WPFunnels",
      "cwe": "CWE-79",
      "title": "WordPress WPFunnels plugin <= 3.13.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97271"
    },
    {
      "rank": 408,
      "cve_id": "CVE-2026-97272",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Premmerce",
      "product": "Premmerce Permalink Manager for WooCommerce",
      "cwe": "CWE-79",
      "title": "WordPress Premmerce Permalink Manager for WooCommerce plugin <= 2.3.13 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97272"
    },
    {
      "rank": 409,
      "cve_id": "CVE-2026-97289",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ExpressTech Systems",
      "product": "Quiz And Survey Master",
      "cwe": "CWE-79",
      "title": "WordPress Quiz And Survey Master plugin <= 11.2.6 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97289"
    },
    {
      "rank": 410,
      "cve_id": "CVE-2026-97290",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sayontan Sinha",
      "product": "Photonic Gallery & Lightbox for Flickr, SmugMug & Others",
      "cwe": "CWE-79",
      "title": "WordPress Photonic Gallery & Lightbox for Flickr, SmugMug & Others plugin <= 3.36 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97290"
    },
    {
      "rank": 411,
      "cve_id": "CVE-2026-100507",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "If-So Dynamic Content",
      "product": "If-So Dynamic Content Personalization",
      "cwe": "CWE-79",
      "title": "WordPress If-So Dynamic Content Personalization plugin <= 1.10.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100507"
    },
    {
      "rank": 412,
      "cve_id": "CVE-2026-100510",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BoldGrid",
      "product": "Post and Page Builder by BoldGrid",
      "cwe": "CWE-79",
      "title": "WordPress Post and Page Builder by BoldGrid plugin <= 1.27.14 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100510"
    },
    {
      "rank": 413,
      "cve_id": "CVE-2026-101879",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw Windows Node",
      "cwe": "CWE-862",
      "title": "OpenClaw Windows Node before 2026.7.1-3 Missing Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101879"
    },
    {
      "rank": 414,
      "cve_id": "CVE-2026-101881",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw Windows Node",
      "cwe": "CWE-770",
      "title": "OpenClaw Windows Node before 2026.7.1 Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101881"
    },
    {
      "rank": 415,
      "cve_id": "CVE-2026-102109",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Secure Data Forms",
      "cwe": "CWE-89",
      "title": "Kiteworks Secure Data Forms SQL injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102109"
    },
    {
      "rank": 416,
      "cve_id": "CVE-2026-102376",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPMU DEV",
      "product": "Branda",
      "cwe": "CWE-79",
      "title": "WordPress Branda plugin <= 3.4.32 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102376"
    },
    {
      "rank": 417,
      "cve_id": "CVE-2026-102385",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kevin Stover",
      "product": "Ninja Forms",
      "cwe": "CWE-79",
      "title": "WordPress Ninja Forms plugin <= 3.15.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102385"
    },
    {
      "rank": 418,
      "cve_id": "CVE-2026-102391",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jetmonsters",
      "product": "JetFormBuilder",
      "cwe": "CWE-79",
      "title": "WordPress JetFormBuilder plugin <= 3.6.5.4 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102391"
    },
    {
      "rank": 419,
      "cve_id": "CVE-2026-102395",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "supsystic",
      "product": "Easy Google Maps",
      "cwe": "CWE-79",
      "title": "WordPress Easy Google Maps plugin <= 1.14.6 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102395"
    },
    {
      "rank": 420,
      "cve_id": "CVE-2026-102396",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "supsystic",
      "product": "Ultimate Maps by Supsystic",
      "cwe": "CWE-79",
      "title": "WordPress Ultimate Maps by Supsystic plugin <= 1.5.5 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102396"
    },
    {
      "rank": 421,
      "cve_id": "CVE-2026-102398",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "supsystic",
      "product": "Popup by Supsystic",
      "cwe": "CWE-79",
      "title": "WordPress Popup by Supsystic plugin <= 1.13.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102398"
    },
    {
      "rank": 422,
      "cve_id": "CVE-2026-103242",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-122",
      "title": "Rpm: heap-based buffer overflow write in hex2binv() via a mistyped rpmtag_filesignatures header tag",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103242"
    },
    {
      "rank": 423,
      "cve_id": "CVE-2026-47582",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-787",
      "title": "NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47582"
    },
    {
      "rank": 424,
      "cve_id": "CVE-2026-47596",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-281",
      "title": "NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user can write to read-only memory because the memory's permissions are not preserved. A successful exploit of this vulnerability might lead to code execution and escalation of privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47596"
    },
    {
      "rank": 425,
      "cve_id": "CVE-2026-47598",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-416",
      "title": "NVIDIA GPU Display Driver for Linux contains a vulnerability in the open-source kernel module event delivery path where an unprivileged local user could cause a use-after-free through a race between asynchronous event delivery and file close. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47598"
    },
    {
      "rank": 426,
      "cve_id": "CVE-2026-102127",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Email Protection Gateway",
      "cwe": "CWE-611",
      "title": "Kiteworks Email Protection Gateway Improper Restriction of XML External Entity Reference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102127"
    },
    {
      "rank": 427,
      "cve_id": "CVE-2026-96342",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Amauri.IO",
      "product": "WPMobile.App",
      "cwe": "CWE-862",
      "title": "WordPress WPMobile.App plugin <= 11.83 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96342"
    },
    {
      "rank": 428,
      "cve_id": "CVE-2026-100275",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-79",
      "title": "In JetBrains YouTrack before 2026.2.19197 stored XSS in the workflow error notification toast was possible",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100275"
    },
    {
      "rank": 429,
      "cve_id": "CVE-2026-103243",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ModelTC",
      "product": "LightLLM",
      "cwe": "CWE-918",
      "title": "LightLLM through 1.2.0 Server-Side Request Forgery via multimodal endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103243"
    },
    {
      "rank": 430,
      "cve_id": "CVE-2026-103476",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yii2-starter-kit",
      "product": "yii2-starter-kit",
      "cwe": "CWE-639",
      "title": "yii2-starter-kit through 4.2.0 Unauthorized File Download via attachment-download",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103476"
    },
    {
      "rank": 431,
      "cve_id": "CVE-2026-103530",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "decolua",
      "product": "9Router",
      "cwe": "CWE-918",
      "title": "decolua 9Router Search Endpoint ssrfGuard.js fetch server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103530"
    },
    {
      "rank": 432,
      "cve_id": "CVE-2026-103592",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pecee",
      "product": "simple-router",
      "cwe": "CWE-348",
      "title": "simple-php-router through 5.4.1.7 IP restriction bypass via forwarding headers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103592"
    },
    {
      "rank": 433,
      "cve_id": "CVE-2026-10726",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cato Networks",
      "product": "SDP Client",
      "cwe": "CWE-73",
      "title": "Cato Windows SDP Client arbitrary file disclosure due to improper TLS certificate validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10726"
    },
    {
      "rank": 434,
      "cve_id": "CVE-2026-96824",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "envato",
      "product": "Template Kit – Import",
      "cwe": "CWE-22",
      "title": "WordPress Template Kit – Import plugin <= 1.0.16 - Arbitrary File Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96824"
    },
    {
      "rank": 435,
      "cve_id": "CVE-2026-97242",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "phuongwebo",
      "product": "WEBO MCP",
      "cwe": "CWE-22",
      "title": "WordPress WEBO MCP plugin <= 3.0.18 - Arbitrary File Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97242"
    },
    {
      "rank": 436,
      "cve_id": "CVE-2026-47509",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-787",
      "title": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47509"
    },
    {
      "rank": 437,
      "cve_id": "CVE-2026-47515",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-125",
      "title": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an out-of-bounds read via an unbounded string operation. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47515"
    },
    {
      "rank": 438,
      "cve_id": "CVE-2026-47522",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-20",
      "title": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause improper input validation. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47522"
    },
    {
      "rank": 439,
      "cve_id": "CVE-2026-47524",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-125",
      "title": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47524"
    },
    {
      "rank": 440,
      "cve_id": "CVE-2026-47525",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-129",
      "title": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an improper validation of an array index. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47525"
    },
    {
      "rank": 441,
      "cve_id": "CVE-2026-47527",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-125",
      "title": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the firmware where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47527"
    },
    {
      "rank": 442,
      "cve_id": "CVE-2026-47529",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-787",
      "title": "NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47529"
    },
    {
      "rank": 443,
      "cve_id": "CVE-2026-47532",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-787",
      "title": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47532"
    },
    {
      "rank": 444,
      "cve_id": "CVE-2026-47533",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-129",
      "title": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an improper validation of an array index. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47533"
    },
    {
      "rank": 445,
      "cve_id": "CVE-2026-47537",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-787",
      "title": "NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47537"
    },
    {
      "rank": 446,
      "cve_id": "CVE-2026-47538",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-787",
      "title": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the firmware where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47538"
    },
    {
      "rank": 447,
      "cve_id": "CVE-2026-47539",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Virtual GPU Manager",
      "cwe": "CWE-681",
      "title": "NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an incorrect numeric conversion. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47539"
    },
    {
      "rank": 448,
      "cve_id": "CVE-2026-47542",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-20",
      "title": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause improper input validation. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47542"
    },
    {
      "rank": 449,
      "cve_id": "CVE-2026-47543",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-20",
      "title": "VIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause improper input validation. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47543"
    },
    {
      "rank": 450,
      "cve_id": "CVE-2026-47544",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Virtual GPU Manager",
      "cwe": "CWE-125",
      "title": "NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47544"
    },
    {
      "rank": 451,
      "cve_id": "CVE-2026-47546",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-20",
      "title": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the firmware where an attacker could cause improper input validation. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47546"
    },
    {
      "rank": 452,
      "cve_id": "CVE-2026-47547",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-20",
      "title": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the firmware where an attacker could cause improper input validation. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47547"
    },
    {
      "rank": 453,
      "cve_id": "CVE-2026-102141",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Core",
      "cwe": "CWE-73",
      "title": "Kiteworks Core Privilege Escalation through External Control of File Name or Path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102141"
    },
    {
      "rank": 454,
      "cve_id": "CVE-2026-102133",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Core",
      "cwe": "CWE-77",
      "title": "Kiteworks Core Arbitrary File Write through Command Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102133"
    },
    {
      "rank": 455,
      "cve_id": "CVE-2026-102135",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Email Protection Gateway",
      "cwe": "CWE-502",
      "title": "Kiteworks Email Protection Gateway Deserialization of Untrusted Data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102135"
    },
    {
      "rank": 456,
      "cve_id": "CVE-2026-102145",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Core",
      "cwe": "CWE-93",
      "title": "Kiteworks Core Server-Side Request Forgery through CRLF Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102145"
    },
    {
      "rank": 457,
      "cve_id": "CVE-2026-62078",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Leap13",
      "product": "Premium Addons for Elementor",
      "cwe": "CWE-79",
      "title": "WordPress Premium Addons for Elementor plugin <= 4.11.105 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62078"
    },
    {
      "rank": 458,
      "cve_id": "CVE-2026-62079",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qode",
      "product": "Qi Addons For Elementor",
      "cwe": "CWE-79",
      "title": "WordPress Qi Addons For Elementor plugin <= 1.11 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62079"
    },
    {
      "rank": 459,
      "cve_id": "CVE-2026-62080",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Leevio",
      "product": "Happy Addons for Elementor",
      "cwe": "CWE-79",
      "title": "WordPress Happy Addons for Elementor plugin <= 3.23.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62080"
    },
    {
      "rank": 460,
      "cve_id": "CVE-2026-62084",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jeff Starr",
      "product": "User Submitted Posts",
      "cwe": "CWE-79",
      "title": "WordPress User Submitted Posts plugin <= 20260810 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62084"
    },
    {
      "rank": 461,
      "cve_id": "CVE-2026-94074",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NSquared",
      "product": "Simply Schedule Appointments",
      "cwe": "CWE-862",
      "title": "WordPress Simply Schedule Appointments plugin <= 1.6.12.29 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94074"
    },
    {
      "rank": 462,
      "cve_id": "CVE-2026-94077",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "10up",
      "product": "Safe SVG",
      "cwe": "CWE-79",
      "title": "WordPress Safe SVG plugin <= 2.5.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94077"
    },
    {
      "rank": 463,
      "cve_id": "CVE-2026-94674",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SweetCode",
      "product": "Pixel Manager for WooCommerce",
      "cwe": "CWE-79",
      "title": "WordPress Pixel Manager for WooCommerce plugin <= 1.69.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94674"
    },
    {
      "rank": 464,
      "cve_id": "CVE-2026-96338",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cozmoslabs",
      "product": "Profile Builder",
      "cwe": "CWE-79",
      "title": "WordPress Profile Builder plugin <= 4.0.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96338"
    },
    {
      "rank": 465,
      "cve_id": "CVE-2026-96347",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bookly",
      "product": "Bookly",
      "cwe": "CWE-639",
      "title": "WordPress Bookly plugin <= 28.2 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96347"
    },
    {
      "rank": 466,
      "cve_id": "CVE-2026-96829",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "POSIMYTH",
      "product": "The Plus Addons for Elementor Page Builder Lite",
      "cwe": "CWE-79",
      "title": "WordPress The Plus Addons for Elementor Page Builder Lite plugin <= 6.5.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96829"
    },
    {
      "rank": 467,
      "cve_id": "CVE-2026-96834",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nexcess",
      "product": "GiveWP",
      "cwe": "CWE-862",
      "title": "WordPress GiveWP plugin <= 4.16.9 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96834"
    },
    {
      "rank": 468,
      "cve_id": "CVE-2026-96835",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "KingAddons.com",
      "product": "King Addons for Elementor",
      "cwe": "CWE-79",
      "title": "WordPress King Addons for Elementor plugin <= 51.1.85 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96835"
    },
    {
      "rank": 469,
      "cve_id": "CVE-2026-97067",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shane Bishop",
      "product": "EWWW Image Optimizer",
      "cwe": "CWE-79",
      "title": "WordPress EWWW Image Optimizer plugin <= 8.7.7 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97067"
    },
    {
      "rank": 470,
      "cve_id": "CVE-2026-97236",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeRex",
      "product": "ThemeREX Addons",
      "cwe": "CWE-79",
      "title": "WordPress ThemeREX Addons plugin < 2.45.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97236"
    },
    {
      "rank": 471,
      "cve_id": "CVE-2026-97239",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jose Conti",
      "product": "MCP Content Manager Lite",
      "cwe": "CWE-862",
      "title": "WordPress MCP Content Manager Lite plugin <= 1.1.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97239"
    },
    {
      "rank": 472,
      "cve_id": "CVE-2026-97247",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Creative Themes",
      "product": "Blocksy Companion",
      "cwe": "CWE-862",
      "title": "WordPress Blocksy Companion plugin <= 2.1.55 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97247"
    },
    {
      "rank": 473,
      "cve_id": "CVE-2026-97262",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Visual Composer",
      "product": "Visual Composer Website Builder",
      "cwe": "CWE-79",
      "title": "WordPress Visual Composer Website Builder plugin <= 45.16.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97262"
    },
    {
      "rank": 474,
      "cve_id": "CVE-2026-97265",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Crocoblock. Jetimpex Inc.",
      "product": "JetEngine",
      "cwe": "CWE-79",
      "title": "WordPress JetEngine plugin <= 3.8.15.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97265"
    },
    {
      "rank": 475,
      "cve_id": "CVE-2026-97266",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nexcess",
      "product": "Virtue/Ascend/Pinnacle Toolkit",
      "cwe": "CWE-79",
      "title": "WordPress Virtue/Ascend/Pinnacle Toolkit plugin <= 4.9.12.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97266"
    },
    {
      "rank": 476,
      "cve_id": "CVE-2026-97270",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Justin Sternberg",
      "product": "CMB2",
      "cwe": "CWE-79",
      "title": "WordPress CMB2 plugin <= 2.13.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97270"
    },
    {
      "rank": 477,
      "cve_id": "CVE-2026-97279",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Chouby",
      "product": "Polylang",
      "cwe": "CWE-79",
      "title": "WordPress Polylang plugin <= 3.8.9 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97279"
    },
    {
      "rank": 478,
      "cve_id": "CVE-2026-97286",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Chill",
      "product": "Strong Testimonials",
      "cwe": "CWE-79",
      "title": "WordPress Strong Testimonials plugin <= 3.3.11 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97286"
    },
    {
      "rank": 479,
      "cve_id": "CVE-2026-97288",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jayson T Cote",
      "product": "OAuth Server",
      "cwe": "CWE-79",
      "title": "WordPress OAuth Server plugin <= 4.5.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97288"
    },
    {
      "rank": 480,
      "cve_id": "CVE-2026-97292",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YITHEMES",
      "product": "YITH WooCommerce Tab Manager",
      "cwe": "CWE-79",
      "title": "WordPress YITH WooCommerce Tab Manager plugin <= 2.15.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97292"
    },
    {
      "rank": 481,
      "cve_id": "CVE-2026-97298",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "KingAddons",
      "product": "King Addons for Elementor",
      "cwe": "CWE-79",
      "title": "WordPress King Addons for Elementor plugin <= 51.1.86 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97298"
    },
    {
      "rank": 482,
      "cve_id": "CVE-2026-97301",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cool Plugins",
      "product": "Cool Formkit Lite",
      "cwe": "CWE-79",
      "title": "WordPress Cool Formkit Lite plugin <= 2.7.8 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97301"
    },
    {
      "rank": 483,
      "cve_id": "CVE-2026-100274",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-770",
      "title": "In JetBrains YouTrack before 2026.2.19197 project Admin could trigger DoS via a notification template",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100274"
    },
    {
      "rank": 484,
      "cve_id": "CVE-2026-100279",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-918",
      "title": "In JetBrains YouTrack before 2026.2.19197 changing an integration URL exposed its stored credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100279"
    },
    {
      "rank": 485,
      "cve_id": "CVE-2026-100513",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Aman",
      "product": "CF7 Views &#8211; Complete Entry Management for Contact Form 7",
      "cwe": "CWE-79",
      "title": "WordPress CF7 Views &#8211; Complete Entry Management for Contact Form 7 plugin <= 3.2.5 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100513"
    },
    {
      "rank": 486,
      "cve_id": "CVE-2026-102124",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Core",
      "cwe": "CWE-306",
      "title": "Kiteworks Core Missing Authentication for Critical Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102124"
    },
    {
      "rank": 487,
      "cve_id": "CVE-2026-102139",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Email Protection Gateway",
      "cwe": "CWE-639",
      "title": "Kiteworks Email Protection Gateway Incorrect Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102139"
    },
    {
      "rank": 488,
      "cve_id": "CVE-2026-102146",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Email Protection Gateway",
      "cwe": "CWE-73",
      "title": "Kiteworks Email Protection Gateway Arbitrary File Write through Server-Side Template Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102146"
    },
    {
      "rank": 489,
      "cve_id": "CVE-2026-102375",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Optimole",
      "product": "Optimole",
      "cwe": "CWE-862",
      "title": "WordPress Optimole plugin <= 4.2.14 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102375"
    },
    {
      "rank": 490,
      "cve_id": "CVE-2026-102386",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jacob N. Breetvelt",
      "product": "WP Photo Album Plus",
      "cwe": "CWE-79",
      "title": "WordPress WP Photo Album Plus plugin <= 9.3.02.003 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102386"
    },
    {
      "rank": 491,
      "cve_id": "CVE-2026-102397",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "supsystic",
      "product": "Ultimate Maps by Supsystic",
      "cwe": "CWE-862",
      "title": "WordPress Ultimate Maps by Supsystic plugin <= 1.5.5 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102397"
    },
    {
      "rank": 492,
      "cve_id": "CVE-2026-102991",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sqlalchemy",
      "product": "mako",
      "cwe": "CWE-22",
      "title": "Mako: Path traversal via drive-letter URI on Windows in TemplateLookup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102991"
    },
    {
      "rank": 493,
      "cve_id": "CVE-2026-103001",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jpadilla",
      "product": "pyjwt",
      "cwe": "CWE-471",
      "title": "PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103001"
    },
    {
      "rank": 494,
      "cve_id": "CVE-2026-47565",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-362",
      "title": "NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a privileged user could trigger a race condition that leads to an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47565"
    },
    {
      "rank": 495,
      "cve_id": "CVE-2026-47586",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-416",
      "title": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel module where an attacker could cause a use-after-free. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47586"
    },
    {
      "rank": 496,
      "cve_id": "CVE-2026-91860",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vaadin",
      "product": "vaadin",
      "cwe": "CWE-1321",
      "title": "Prototype Pollution in Vaadin Charts and Component Base via Unfiltered Deep Merge",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91860"
    },
    {
      "rank": 497,
      "cve_id": "CVE-2026-96821",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mahmudul Hasan Arif",
      "product": "FluentBoards",
      "cwe": "CWE-266",
      "title": "WordPress FluentBoards plugin <= 2.0.12 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96821"
    },
    {
      "rank": 498,
      "cve_id": "CVE-2026-102136",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Core",
      "cwe": "CWE-93",
      "title": "Kiteworks Core Command Execution through Configuration Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102136"
    },
    {
      "rank": 499,
      "cve_id": "CVE-2026-102983",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "withastro",
      "product": "astro",
      "cwe": "CWE-625",
      "title": "Astro: Netlify Image CDN allowlist bypass enables SSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102983"
    },
    {
      "rank": 500,
      "cve_id": "CVE-2026-103222",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Blosc",
      "product": "C-Blosc2",
      "cwe": "CWE-189",
      "title": "Blosc C-Blosc2 blosclz Decompression blosclz.c blosclz_decompress integer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103222"
    },
    {
      "rank": 501,
      "cve_id": "CVE-2026-103397",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Liquid-co",
      "product": "OpenSave",
      "cwe": "CWE-290",
      "title": "OpenSave before 2.4.0-beta.1 Authentication Bypass via Spoofed Relay Sender",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103397"
    },
    {
      "rank": 502,
      "cve_id": "CVE-2026-103388",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-79",
      "title": "MISP Stored Cross-Site Scripting via JavaScript URL in Galaxy Cluster Source Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103388"
    },
    {
      "rank": 503,
      "cve_id": "CVE-2026-103389",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-20",
      "title": "MISP Stored Cross-Site Scripting via Unvalidated Galaxy Icon Field in Correlation Graph",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103389"
    },
    {
      "rank": 504,
      "cve_id": "CVE-2026-47518",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-732",
      "title": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in a secure microcontroller component, where incorrect permission assignment for a critical resource allows an attacker with privileged local access to modify protected memory that should be restricted. A successful exploit of this vulnerability might lead to code execution and escalation of privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47518"
    },
    {
      "rank": 505,
      "cve_id": "CVE-2026-55174",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shrec",
      "product": "UltrafastSecp256k1",
      "cwe": "CWE-345",
      "title": "UltrafastSecp256k1: ECDSA adaptor verification accepts non-adaptable pre-signatures due to missing DLEQ binding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55174"
    },
    {
      "rank": 506,
      "cve_id": "CVE-2026-94681",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tijmen Smit",
      "product": "WP Store Locator",
      "cwe": "CWE-770",
      "title": "WordPress WP Store Locator plugin < 3.0.0 - Denial of Service Attack vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94681"
    },
    {
      "rank": 507,
      "cve_id": "CVE-2026-100267",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-1333",
      "title": "In JetBrains YouTrack before 2026.2.19197 reDoS attack was possible via mailbox regex mail-rule filters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100267"
    },
    {
      "rank": 508,
      "cve_id": "CVE-2026-100276",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-863",
      "title": "In JetBrains YouTrack before 2026.2.19197 guest users could remove a workflow action's visibility restriction and run the action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100276"
    },
    {
      "rank": 509,
      "cve_id": "CVE-2026-102110",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Core",
      "cwe": "CWE-306",
      "title": "Missing authentication on a Kiteworks appliance setup function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102110"
    },
    {
      "rank": 510,
      "cve_id": "CVE-2026-102384",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Supreme Modules",
      "product": "Supreme Modules Lite",
      "cwe": "CWE-79",
      "title": "WordPress Supreme Modules Lite plugin <= 2.5.63 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102384"
    },
    {
      "rank": 511,
      "cve_id": "CVE-2026-47492",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-862",
      "title": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an attacker can cause improper access control. A successful exploit of this vulnerability might lead to denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47492"
    },
    {
      "rank": 512,
      "cve_id": "CVE-2026-47506",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-121",
      "title": "NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel-mode color transform path where excessive kernel stack use occurs when evaluating YCbCr420 display emulation. A successful exploit of this vulnerability might lead to denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47506"
    },
    {
      "rank": 513,
      "cve_id": "CVE-2026-47517",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-476",
      "title": "NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode driver where a local user may cause a null pointer dereference by submitting a crafted ioctl. A successful exploit of this vulnerability might lead to denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47517"
    },
    {
      "rank": 514,
      "cve_id": "CVE-2026-47534",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-369",
      "title": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause a divide by zero. A successful exploit of this vulnerability might lead to denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47534"
    },
    {
      "rank": 515,
      "cve_id": "CVE-2026-47549",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-476",
      "title": "NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel module where an unprivileged local user could cause a NULL pointer dereference. A successful exploit of this vulnerability might lead to denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47549"
    },
    {
      "rank": 516,
      "cve_id": "CVE-2026-47555",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-908",
      "title": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where a user could cause uninitialized kernel memory to be copied back to userspace. A successful exploit of this vulnerability might lead to information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47555"
    },
    {
      "rank": 517,
      "cve_id": "CVE-2026-47557",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-476",
      "title": "NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user could cause a NULL pointer dereference. A successful exploit of this vulnerability might lead to denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47557"
    },
    {
      "rank": 518,
      "cve_id": "CVE-2026-47566",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-401",
      "title": "NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user could cause a memory leak in error paths leading to kernel memory exhaustion. A successful exploit of this vulnerability might lead to denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47566"
    },
    {
      "rank": 519,
      "cve_id": "CVE-2026-47567",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-400",
      "title": "NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where a user could cause uncontrolled resource consumption by exhausting the DRM VMA offset address space. A successful exploit of this vulnerability might lead to denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47567"
    },
    {
      "rank": 520,
      "cve_id": "CVE-2026-47568",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-400",
      "title": "NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a user could cause uncontrolled kernel log generation by repeatedly invoking an interface that emits unrate-limited error messages. A successful exploit of this vulnerability might lead to denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47568"
    },
    {
      "rank": 521,
      "cve_id": "CVE-2026-47581",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-667",
      "title": "NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where a user could cause improper locking. A successful exploit of this vulnerability might lead to denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47581"
    },
    {
      "rank": 522,
      "cve_id": "CVE-2026-47584",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-476",
      "title": "NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where an attacker with local access could cause a NULL pointer dereference. A successful exploit of this vulnerability might lead to denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47584"
    },
    {
      "rank": 523,
      "cve_id": "CVE-2026-47603",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-862",
      "title": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode driver where a local user may access another process's GPU channel state due to missing authorization checks. A successful exploit of this vulnerability might lead to information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47603"
    },
    {
      "rank": 524,
      "cve_id": "CVE-2026-47604",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-862",
      "title": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode driver where a local user may access another process's GPU channel state due to missing authorization checks. A successful exploit of this vulnerability might lead to information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47604"
    },
    {
      "rank": 525,
      "cve_id": "CVE-2026-97238",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Crocoblock. Jetimpex Inc.",
      "product": "JetEngine",
      "cwe": "CWE-79",
      "title": "WordPress JetEngine plugin <= 3.8.14.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97238"
    },
    {
      "rank": 526,
      "cve_id": "CVE-2026-103229",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AdithyaYelloju",
      "product": "Restaurant-Management-System",
      "cwe": "CWE-74",
      "title": "AdithyaYelloju Restaurant-Management-System Unauthenticated Action Script delete1.php mysqli_query sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103229"
    },
    {
      "rank": 527,
      "cve_id": "CVE-2026-103230",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AdithyaYelloju",
      "product": "Restaurant-Management-System",
      "cwe": "CWE-74",
      "title": "AdithyaYelloju Restaurant-Management-System Order Placement ord.php mysqli_query sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103230"
    },
    {
      "rank": 528,
      "cve_id": "CVE-2026-103231",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AdithyaYelloju",
      "product": "Restaurant-Management-System",
      "cwe": "CWE-74",
      "title": "AdithyaYelloju Restaurant-Management-System Order Cancellation cancel.php mysqli_query sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103231"
    },
    {
      "rank": 529,
      "cve_id": "CVE-2026-103232",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AdithyaYelloju",
      "product": "Restaurant-Management-System",
      "cwe": "CWE-74",
      "title": "AdithyaYelloju Restaurant-Management-System table_booking.php mysqli_query sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103232"
    },
    {
      "rank": 530,
      "cve_id": "CVE-2026-103241",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vLLM",
      "cwe": "CWE-404",
      "title": "vllm-project vLLM Gemma4UnifiedParser gemma4.rs denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103241"
    },
    {
      "rank": 531,
      "cve_id": "CVE-2026-13720",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Grafana",
      "product": "Grafana OSS",
      "cwe": "CWE-285",
      "title": "Editor can forge file-provisioning provenance on dashboards via the dashboard API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13720"
    },
    {
      "rank": 532,
      "cve_id": "CVE-2026-62081",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpdesk",
      "product": "Flexible PDF Coupons",
      "cwe": "CWE-639",
      "title": "WordPress Flexible PDF Coupons plugin <= 1.14.11 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62081"
    },
    {
      "rank": 533,
      "cve_id": "CVE-2026-62083",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPFunnels",
      "product": "Creator LMS",
      "cwe": "CWE-1284",
      "title": "WordPress Creator LMS plugin <= 1.2.19 - Other vulnerability Type vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62083"
    },
    {
      "rank": 534,
      "cve_id": "CVE-2026-94173",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Strategy11 Team",
      "product": "Business Directory",
      "cwe": "CWE-639",
      "title": "WordPress Business Directory plugin <= 6.4.27 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94173"
    },
    {
      "rank": 535,
      "cve_id": "CVE-2026-96450",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pixfort",
      "product": "pixfort Core",
      "cwe": "CWE-79",
      "title": "WordPress pixfort Core plugin < 4.3.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96450"
    },
    {
      "rank": 536,
      "cve_id": "CVE-2026-97243",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "flexyma",
      "product": "AllAble Connector",
      "cwe": "CWE-862",
      "title": "WordPress AllAble Connector plugin <= 0.13.4 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97243"
    },
    {
      "rank": 537,
      "cve_id": "CVE-2026-97285",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nexcess",
      "product": "The Events Calendar",
      "cwe": "CWE-862",
      "title": "WordPress The Events Calendar plugin <= 6.17.5 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97285"
    },
    {
      "rank": 538,
      "cve_id": "CVE-2026-97299",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "KnitPay",
      "product": "Razorpay Payment Links for WooCommerce",
      "cwe": "CWE-352",
      "title": "WordPress Razorpay Payment Links for WooCommerce plugin <= 2.1.5 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97299"
    },
    {
      "rank": 539,
      "cve_id": "CVE-2026-100261",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-288",
      "title": "In JetBrains YouTrack before 2026.2.18991 changing article visibility settings was possible without update permission",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100261"
    },
    {
      "rank": 540,
      "cve_id": "CVE-2026-102134",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Core",
      "cwe": "CWE-420",
      "title": "Kiteworks Core Unprotected Alternate Channel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102134"
    },
    {
      "rank": 541,
      "cve_id": "CVE-2026-102399",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "supsystic",
      "product": "Photo Gallery by Supsystic",
      "cwe": "CWE-352",
      "title": "WordPress Photo Gallery by Supsystic plugin <= 1.21.0 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102399"
    },
    {
      "rank": 542,
      "cve_id": "CVE-2026-47096",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AJA Video Systems",
      "product": "HELO Plus",
      "cwe": "CWE-79",
      "title": "AJA HELO Plus < 2.1.7 Stored XSS via System Name Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47096"
    },
    {
      "rank": 543,
      "cve_id": "CVE-2026-86778",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Maksisoft Technology, IT, and Software Industry and Trade Inc.",
      "product": "Maksisoft Gym",
      "cwe": "CWE-204",
      "title": "Username Enumeration in Maksisoft Technology's Maksisoft Gym",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86778"
    },
    {
      "rank": 544,
      "cve_id": "CVE-2026-93547",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vaadin",
      "product": "vaadin",
      "cwe": "CWE-285",
      "title": "Missing Authorization Check in Vaadin Spreadsheet Allows Cell Comments to Be Written to Protected Sheets and Locked Cells",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93547"
    },
    {
      "rank": 545,
      "cve_id": "CVE-2026-94545",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vercel",
      "product": "satori",
      "cwe": "CWE-116",
      "title": "Satori-generated SVG has improper escaping",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94545"
    },
    {
      "rank": 546,
      "cve_id": "CVE-2026-94673",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NSquared",
      "product": "Simply Schedule Appointments",
      "cwe": "CWE-639",
      "title": "WordPress Simply Schedule Appointments plugin <= 1.6.12.31 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94673"
    },
    {
      "rank": 547,
      "cve_id": "CVE-2026-97066",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nexcess",
      "product": "GiveWP",
      "cwe": "CWE-639",
      "title": "WordPress GiveWP plugin <= 4.16.9 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97066"
    },
    {
      "rank": 548,
      "cve_id": "CVE-2026-97078",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BoldGrid",
      "product": "Client Invoicing by Sprout Invoices",
      "cwe": "CWE-639",
      "title": "WordPress Client Invoicing by Sprout Invoices plugin <= 20.8.17 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97078"
    },
    {
      "rank": 549,
      "cve_id": "CVE-2026-97249",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cozmoslabs",
      "product": "Paid Member Subscriptions",
      "cwe": "CWE-290",
      "title": "WordPress Paid Member Subscriptions plugin <= 3.0.9 - Bypass Vulnerability vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97249"
    },
    {
      "rank": 550,
      "cve_id": "CVE-2026-97259",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Hosting AS",
      "product": "Pay with Vipps for WooCommerce",
      "cwe": "CWE-639",
      "title": "WordPress Pay with Vipps for WooCommerce plugin <= 6.2.4 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97259"
    },
    {
      "rank": 551,
      "cve_id": "CVE-2026-97261",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VillaTheme",
      "product": "Notivo",
      "cwe": "CWE-201",
      "title": "WordPress Notivo plugin <= 1.4.2 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97261"
    },
    {
      "rank": 552,
      "cve_id": "CVE-2026-97282",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RadiusTheme",
      "product": "Review Schema",
      "cwe": "CWE-639",
      "title": "WordPress Review Schema plugin <= 3.1.0 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97282"
    },
    {
      "rank": 553,
      "cve_id": "CVE-2026-97302",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themeisle",
      "product": "MPG",
      "cwe": "CWE-201",
      "title": "WordPress MPG plugin <= 4.2.3 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97302"
    },
    {
      "rank": 554,
      "cve_id": "CVE-2026-100260",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-1188",
      "title": "In JetBrains YouTrack before 2026.2.18991 mailbox integration allowed authentication after a password reset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100260"
    },
    {
      "rank": 555,
      "cve_id": "CVE-2026-100508",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WordPress.org",
      "product": "Two Factor",
      "cwe": "CWE-770",
      "title": "WordPress Two Factor plugin <= 0.16.0 - Denial of Service Attack vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100508"
    },
    {
      "rank": 556,
      "cve_id": "CVE-2026-101883",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw Windows Node",
      "cwe": "CWE-918",
      "title": "OpenClaw Windows Node through 2026.9.4 SSRF via canvas.present",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101883"
    },
    {
      "rank": 557,
      "cve_id": "CVE-2026-102144",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Email Protection Gateway",
      "cwe": "CWE-306",
      "title": "Kiteworks Email Protection Gateway Uncontrolled Resource Consumption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102144"
    },
    {
      "rank": 558,
      "cve_id": "CVE-2026-103118",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "GraphicsMagick",
      "cwe": "CWE-404",
      "title": "GraphicsMagick WPG File wpg.c ExtractPostscript recursion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103118"
    },
    {
      "rank": 559,
      "cve_id": "CVE-2026-103227",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "GPAC",
      "cwe": "CWE-119",
      "title": "GPAC DASH Client dash_client.c gf_dash_resolve_url buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103227"
    },
    {
      "rank": 560,
      "cve_id": "CVE-2026-103396",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mlogclub",
      "product": "bbs-go",
      "cwe": "CWE-863",
      "title": "bbs-go through 4.4.6 Incorrect Authorization via /api/admin/user/synccount",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103396"
    },
    {
      "rank": 561,
      "cve_id": "CVE-2026-103399",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-444",
      "title": "Libsoup: soupserver: http/1 request smuggling via undrained expect: 100-continue body",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103399"
    },
    {
      "rank": 562,
      "cve_id": "CVE-2026-103548",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Itron",
      "product": "MV-90 xi",
      "cwe": "CWE-257",
      "title": "Improperly Stored Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103548"
    },
    {
      "rank": 563,
      "cve_id": "CVE-2026-103587",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webkul",
      "product": "QloApps",
      "cwe": "CWE-79",
      "title": "QloApps through 1.7.0 Reflected XSS via Book Now Search Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103587"
    },
    {
      "rank": 564,
      "cve_id": "CVE-2026-103588",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webkul",
      "product": "QloApps",
      "cwe": "CWE-79",
      "title": "QloApps through 1.7.0 Reflected XSS via exceptions field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103588"
    },
    {
      "rank": 565,
      "cve_id": "CVE-2026-103589",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webkul",
      "product": "QloApps",
      "cwe": "CWE-79",
      "title": "QloApps through 1.7.0 Reflected XSS via Room Type Editor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103589"
    },
    {
      "rank": 566,
      "cve_id": "CVE-2026-103590",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webkul",
      "product": "QloApps",
      "cwe": "CWE-79",
      "title": "QloApps through 1.7.0 Reflected XSS via Length of Stay Fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103590"
    },
    {
      "rank": 567,
      "cve_id": "CVE-2026-97246",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ShortPixel",
      "product": "ShortPixel Image Optimizer",
      "cwe": "CWE-502",
      "title": "WordPress ShortPixel Image Optimizer plugin <= 6.5.5 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97246"
    },
    {
      "rank": 568,
      "cve_id": "CVE-2026-100272",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-639",
      "title": "In JetBrains YouTrack before 2026.2.19197 missing authorisation in the notification template preview allowed Project Administrators to read restricted issues",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100272"
    },
    {
      "rank": 569,
      "cve_id": "CVE-2026-100278",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-863",
      "title": "In JetBrains YouTrack before 2026.2.19197 users with restricted permission could edit and hide other users' comments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100278"
    },
    {
      "rank": 570,
      "cve_id": "CVE-2026-102111",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Core",
      "cwe": "CWE-1284",
      "title": "Kiteworks Core Improper Validation of Specified Quantity in Input",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102111"
    },
    {
      "rank": 571,
      "cve_id": "CVE-2026-102140",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Core",
      "cwe": "CWE-345",
      "title": "Kiteworks Core Insufficient Verification of Data Authenticity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102140"
    },
    {
      "rank": 572,
      "cve_id": "CVE-2026-92899",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache WSS4J",
      "cwe": "CWE-290",
      "title": "Apache WSS4J: UsernameToken replay protection bypassed by re-encoding the Nonce",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92899"
    },
    {
      "rank": 573,
      "cve_id": "CVE-2026-100265",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "Rider",
      "cwe": "CWE-494",
      "title": "In JetBrains Rider before 2026.2.1 aI Assistant could auto-update third-party skills without user confirmation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100265"
    },
    {
      "rank": 574,
      "cve_id": "CVE-2026-100263",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-79",
      "title": "In JetBrains YouTrack before 2026.2.18991 stored HTML injection via the User-Agent header was possible",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100263"
    },
    {
      "rank": 575,
      "cve_id": "CVE-2026-102107",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Core",
      "cwe": "CWE-639",
      "title": "Kiteworks Core user impersonation in a file-request feature",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102107"
    },
    {
      "rank": 576,
      "cve_id": "CVE-2026-47526",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-476",
      "title": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the firmware where an attacker could cause a null pointer dereference. A successful exploit of this vulnerability might lead to denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47526"
    },
    {
      "rank": 577,
      "cve_id": "CVE-2026-47531",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-476",
      "title": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause a null pointer dereference. A successful exploit of this vulnerability might lead to denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47531"
    },
    {
      "rank": 578,
      "cve_id": "CVE-2026-47562",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-116",
      "title": "NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a user could inject crafted text into the kernel log because the supplied version string is not properly sanitized. A successful exploit of this vulnerability might lead to denial of service and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47562"
    },
    {
      "rank": 579,
      "cve_id": "CVE-2026-13719",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Grafana",
      "product": "Grafana Enterprise",
      "cwe": "CWE-200",
      "title": "Alert rules in restricted folders disclosed via the alert rules list API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13719"
    },
    {
      "rank": 580,
      "cve_id": "CVE-2026-94672",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "10up",
      "product": "Safe SVG",
      "cwe": "CWE-639",
      "title": "WordPress Safe SVG plugin <= 2.5.0 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94672"
    },
    {
      "rank": 581,
      "cve_id": "CVE-2026-97074",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Omnisend",
      "product": "Newsletters, Email Marketing, SMS and Popups by Omnisend",
      "cwe": "CWE-639",
      "title": "WordPress Newsletters, Email Marketing, SMS and Popups by Omnisend plugin <= 1.9.0 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97074"
    },
    {
      "rank": 582,
      "cve_id": "CVE-2026-97079",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webba Appointment Booking",
      "product": "Webba Booking",
      "cwe": "CWE-639",
      "title": "WordPress Webba Booking plugin <= 6.5.0 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97079"
    },
    {
      "rank": 583,
      "cve_id": "CVE-2026-97267",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "miniOrange",
      "product": "Prevent files / folders access",
      "cwe": "CWE-862",
      "title": "WordPress Prevent files / folders access plugin <= 2.6.7 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97267"
    },
    {
      "rank": 584,
      "cve_id": "CVE-2026-100257",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-918",
      "title": "In JetBrains YouTrack before 2026.2.18991 sSRF via stored XHTML injection was possible during PDF export",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100257"
    },
    {
      "rank": 585,
      "cve_id": "CVE-2026-100258",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-201",
      "title": "In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed read-only users to read project settings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100258"
    },
    {
      "rank": 586,
      "cve_id": "CVE-2026-100259",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-863",
      "title": "In JetBrains YouTrack before 2026.2.18991 improper access control on Gantt chart allowed edits by users with view-only access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100259"
    },
    {
      "rank": 587,
      "cve_id": "CVE-2026-100269",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-862",
      "title": "In JetBrains YouTrack before 2026.2.19197 helpdesk project's Authorized Reporters list could be bypassed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100269"
    },
    {
      "rank": 588,
      "cve_id": "CVE-2026-102090",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Core",
      "cwe": "CWE-601",
      "title": "Kiteworks Core content injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102090"
    },
    {
      "rank": 589,
      "cve_id": "CVE-2026-102122",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Core",
      "cwe": "CWE-863",
      "title": "Kiteworks Core Incorrect Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102122"
    },
    {
      "rank": 590,
      "cve_id": "CVE-2026-96825",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "David Anderson / Team Updraft",
      "product": "All In One WP Security & Firewall",
      "cwe": "CWE-290",
      "title": "WordPress All In One WP Security & Firewall plugin <= 5.4.8 - Bypass Vulnerability vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96825"
    },
    {
      "rank": 591,
      "cve_id": "CVE-2026-102137",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Core",
      "cwe": "CWE-434",
      "title": "Kiteworks Core Unrestricted Upload of File with Dangerous Type",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102137"
    },
    {
      "rank": 592,
      "cve_id": "CVE-2026-103436",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "apcupsd",
      "product": "apcupsd",
      "cwe": "CWE-457",
      "title": "apcupsd through 3.14.14 discloses uninitialized stack memory in getupsvar() in src/cgi/upsfetch.c (used by upsstats.cgi, multimon.cgi, and upsfstats.cgi. On the single-field path, when the matched STATUS line has fewer than three whitespace-separated tokens, sscanf(\"%*s %*s %s\", answer) performs no assignment but the function returns success, and thus the caller prints the uninitialized destination buffer into the HTTP response.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103436"
    },
    {
      "rank": 593,
      "cve_id": "CVE-2026-100270",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-863",
      "title": "In JetBrains YouTrack before 2026.2.19197 low-level Admin Read permission users could disclose integration credentials via import configurations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100270"
    },
    {
      "rank": 594,
      "cve_id": "CVE-2026-102138",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiteworks",
      "product": "Core",
      "cwe": "CWE-918",
      "title": "Kiteworks Core Server-Side Request Forgery (SSRF)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102138"
    },
    {
      "rank": 595,
      "cve_id": "CVE-2026-100280",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-862",
      "title": "In JetBrains YouTrack before 2026.2.19197 creating a project from an unreadable custom template was possible",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100280"
    },
    {
      "rank": 596,
      "cve_id": "CVE-2026-27085",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Brainstorm Force",
      "product": "Astra WordPress Theme",
      "cwe": "CWE-80",
      "title": "WordPress Astra WordPress theme theme <= 4.13.12 - Content Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27085"
    },
    {
      "rank": 597,
      "cve_id": "CVE-2026-100264",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-522",
      "title": "In JetBrains YouTrack before 2026.2.18991 stored SMTP server credentials could be disclosed by changing the server host",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100264"
    },
    {
      "rank": 598,
      "cve_id": "CVE-2026-100271",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-862",
      "title": "In JetBrains YouTrack before 2026.2.19197 missing authorisation on several endpoints allowed authenticated users to access information from other projects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100271"
    },
    {
      "rank": 599,
      "cve_id": "CVE-2026-103114",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OS4ED",
      "product": "openSIS-Classic",
      "cwe": "CWE-74",
      "title": "OS4ED openSIS-Classic Assignment Management Endpoint Assignments.php DBQuery_assignment sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103114"
    },
    {
      "rank": 600,
      "cve_id": "CVE-2026-103115",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OS4ED",
      "product": "openSIS-Classic",
      "cwe": "CWE-74",
      "title": "OS4ED openSIS-Classic Student Search CustomFieldsFnc.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103115"
    },
    {
      "rank": 601,
      "cve_id": "CVE-2026-103116",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OS4ED",
      "product": "openSIS-Classic",
      "cwe": "CWE-74",
      "title": "OS4ED openSIS-Classic Student List Search Endpoint GetStuListFnc.php DBQuery sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103116"
    },
    {
      "rank": 602,
      "cve_id": "CVE-2026-103226",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Artifex",
      "product": "Ghostscript",
      "cwe": "CWE-119",
      "title": "Artifex Ghostscript Pdfwrite gdevpsfx.c type1_callsubr stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103226"
    },
    {
      "rank": 603,
      "cve_id": "CVE-2026-103233",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AdithyaYelloju",
      "product": "Restaurant-Management-System",
      "cwe": "CWE-285",
      "title": "AdithyaYelloju Restaurant-Management-System Admin Area admin authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103233"
    },
    {
      "rank": 604,
      "cve_id": "CVE-2026-103387",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "garycourt",
      "product": "uri-js",
      "cwe": "CWE-248",
      "title": "garycourt uri-js Mailto Header mailto.ts URI.parse uncaught exception",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103387"
    },
    {
      "rank": 605,
      "cve_id": "CVE-2026-103012",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Anthropic",
      "product": "@anthropic-ai/claude-code",
      "cwe": "CWE-696",
      "title": "Claude Code selected an API key stored by Claude Code, for example from an earlier `/login` or written directly to its configuration, ahead of the user's valid Claude Enterprise or Team sign-in when fetching the organization's server-managed settings, even though the session itself authenticated with the Enterprise or Team account. When the settings endpoint rejected that stored key, the session started without the organization's server-managed policy (such as permission deny rules, model restrictions and managed-only locks) or, if a previously cached copy existed on the machine, kept applying that stale copy without receiving later policy changes — while continuing to operate as the organization's account. Triggering this required local access to a device with such a stored API key; the no-policy case additionally required that no managed settings had previously been cached. Endpoint-managed (MDM or file-based) settings were not affected. Claude for Enterprise organizations were affected from version 2.0.68; Claude for Work (Team) organizations from version 2.1.38, when server-managed settings became available to them. Users on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to version 2.1.260 or later. Thank you to Tamas Voros / NVIDIA AI Red Team for reporting this issue.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103012"
    },
    {
      "rank": 606,
      "cve_id": "CVE-2026-103113",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OS4ED",
      "product": "openSIS-Classic",
      "cwe": "CWE-74",
      "title": "OS4ED openSIS-Classic General Information Tab Student.php save action sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103113"
    },
    {
      "rank": 607,
      "cve_id": "CVE-2026-103117",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OS4ED",
      "product": "openSIS-Classic",
      "cwe": "CWE-74",
      "title": "OS4ED openSIS-Classic Save Data DatabaseInc.php db_properties sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103117"
    },
    {
      "rank": 608,
      "cve_id": "CVE-2026-103440",
      "cvss_base": 1.2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Wikimedia Foundation",
      "product": "MediaWiki PageTriage extension",
      "cwe": "CWE-202",
      "title": "pagetriagelist discloses suppressed reviewer usernames",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103440"
    },
    {
      "rank": 609,
      "cve_id": "CVE-2026-103445",
      "cvss_base": 1.2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Wikimedia Foundation",
      "product": "MediaWiki Page_Forms extension",
      "cwe": "CWE-80",
      "title": "Stored XSS through PageForms #autoedit redirect links",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103445"
    },
    {
      "rank": 610,
      "cve_id": "CVE-2026-103585",
      "cvss_base": 1.2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Wikimedia Foundation",
      "product": "MediaWiki MediaSearch extension",
      "cwe": "CWE-80",
      "title": "attacker-controlled javascript license URL via XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103585"
    },
    {
      "rank": 611,
      "cve_id": "CVE-2026-103437",
      "cvss_base": 1.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Wikimedia Foundation",
      "product": "MediaWiki ReadingLists extension",
      "cwe": "CWE-80",
      "title": "ReadingLists imported metadata permits JavaScript URL XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103437"
    },
    {
      "rank": 612,
      "cve_id": "CVE-2026-103443",
      "cvss_base": 1.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Wikimedia Foundation",
      "product": "MediaWiki Collection (Book) extension",
      "cwe": "CWE-80",
      "title": "API permits session-seeded javascript URL XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103443"
    },
    {
      "rank": 613,
      "cve_id": "CVE-2026-103444",
      "cvss_base": 1.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Wikimedia Foundation",
      "product": "MediaWiki WikiForum extension",
      "cwe": "CWE-80",
      "title": "Stored XSS through system messages in WikiForum",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103444"
    },
    {
      "rank": 614,
      "cve_id": "CVE-2026-103584",
      "cvss_base": 1.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Wikimedia Foundation",
      "product": "MediaWiki CommonsMetadata extension",
      "cwe": "CWE-80",
      "title": "attacker-controlled javascript license URL via XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103584"
    },
    {
      "rank": 615,
      "cve_id": "CVE-2026-103438",
      "cvss_base": 0.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Wikimedia Foundation",
      "product": "MediaWiki Wikistories extension",
      "cwe": "CWE-80",
      "title": "Various rawParams() and escaped() updates to prevent XSS in Wikistories extension",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103438"
    },
    {
      "rank": 616,
      "cve_id": "CVE-2026-103439",
      "cvss_base": 0.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Wikimedia Foundation",
      "product": "MediaWiki Wikbase extension",
      "cwe": "CWE-80",
      "title": "Various rawParams() and escaped() updates to prevent XSS in Wikibase extension",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103439"
    },
    {
      "rank": 617,
      "cve_id": "CVE-2026-51852",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "agent-zero 1.7, 1.8, 1.9, and 1.10 is vulnerable to Directory Traversal in python/helpers/file_browser.py:FileBrowser.save_file_b64. The save_file_b64 method accepts user-controlled file paths without normalization or validation, allowing path traversal attacks.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51852"
    },
    {
      "rank": 618,
      "cve_id": "CVE-2026-51853",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "agent-zero 1.7, 1.8, 1.9, and 1.10 is vulnerable to Directory Traversal in python/helpers/file_browser.py:FileBrowser.__init__. The FileBrowser class initializes with the host root directory as the workspace, allowing the agent to access any file on the system without restriction.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51853"
    },
    {
      "rank": 619,
      "cve_id": "CVE-2026-51856",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "In agentscope 1.0.18, 1.0.19, and 1.0.19 when the RealtimeAgent session exposes execute_python_code as an available tool, a remote WebSocket user can prompt the agent to call that tool and run Python code in the service environment. In the validated path, RealtimeAgent._acting forwards the model-produced tool call to Toolkit.call_tool_function, which invokes execute_python_code without an additional approval or isolation boundary on that path.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51856"
    },
    {
      "rank": 620,
      "cve_id": "CVE-2026-51857",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "In camel-ai camel 0.2.91a1, v0.2.91a2 and v0.2.91a3, CodeExecutionToolkit can run model-produced Python code through SubprocessInterpreter without an approval boundary.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51857"
    },
    {
      "rank": 621,
      "cve_id": "CVE-2026-51858",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "In camel-ai camel 0.2.91a1, v0.2.91a2 and v0.2.91a3, TerminalToolkit.shell_exec allows prompt-driven shell command execution without an approval boundary.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51858"
    },
    {
      "rank": 622,
      "cve_id": "CVE-2026-51859",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "bisheng 2.3.0, 2.4.0, and 2.4.0-beta1 is vulnerable to directory traversal in save_download_file (src/backend/bisheng/core/cache/utils.py:290).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51859"
    },
    {
      "rank": 623,
      "cve_id": "CVE-2026-51860",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "bisheng 2.3.0, 2.4.0, and 2.4.0-beta1 is vulnerable to Directory Traversal in src/backend/bisheng/linsight/domain/task_exec.py.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51860"
    },
    {
      "rank": 624,
      "cve_id": "CVE-2026-51861",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "bisheng 2.3.0, 2.4.0, and 2.4.0-beta1 is vulnerable to Code Injection in src/backend/bisheng/api/v1/validate.py.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51861"
    },
    {
      "rank": 625,
      "cve_id": "CVE-2026-51862",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "DB-GPT 0.8.0 contains directory traversal in skill_upload (packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py:40). A remote attacker can use the validated exploitation path to write files outside the intended workspace or storage boundary.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51862"
    },
    {
      "rank": 626,
      "cve_id": "CVE-2026-51864",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "DB-GPT v0.7.5 and v0.8.0 contains directory traversal in python_file_upload (packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/python_upload_api.py:42). A remote attacker can use the validated exploitation path to write files outside the intended workspace or storage boundary.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51864"
    },
    {
      "rank": 627,
      "cve_id": "CVE-2026-51866",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "In DB-GPT 0.7.5 and 0.8.0, a skill uploaded through the real /api/v1/skills/upload route can later be executed through the real /api/v1/chat/react-agent flow.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51866"
    },
    {
      "rank": 628,
      "cve_id": "CVE-2026-51867",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "agentgpt v.1.0.0 is vulnerable to Incorrect Access Control in next/src/server/api/routers/agentRouter.ts. An externally reachable path accepts a caller-selected object or tenant identifier and reaches a data-access operation without a visible owner, tenant, workspace, or membership binding on that object.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51867"
    },
    {
      "rank": 629,
      "cve_id": "CVE-2026-51869",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "DB-GPT v0.8.0 sandbox API silently falls back to LocalRuntime and executes code on host.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51869"
    },
    {
      "rank": 630,
      "cve_id": "CVE-2026-51870",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "DeepTutor v1.4.0 is vulnerable to command execution in /tutorbot/agent/tools/shell.py:ExecTool.execute.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51870"
    },
    {
      "rank": 631,
      "cve_id": "CVE-2026-51871",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Devika v1.0 is vulnerable to Code Injection in the Runner.execute function in src/agents/runner/runner.py which allows an attacker to achieve arbitrary code execution by exploiting the direct execution of LLM-generated content.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51871"
    },
    {
      "rank": 632,
      "cve_id": "CVE-2026-51872",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Devika v1.0 is vulnerable to Code Injection via the Runner.run_code function in src/agents/runner/runner.py.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51872"
    },
    {
      "rank": 633,
      "cve_id": "CVE-2026-80490",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "Algorithm-AhoCorasick-XS",
      "cwe": "CWE-125",
      "title": "Algorithm::AhoCorasick::XS versions through 0.04 for Perl read the haystack string length before the scalar is stringified",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80490"
    },
    {
      "rank": 634,
      "cve_id": "CVE-2026-92172",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Meta Platforms, Inc",
      "product": "Meta Horizon OS",
      "cwe": null,
      "title": "Prior to v66.0.0.733.524 of Meta Horizon OS, OVRMediaService could be induced to send a privileged PendingIntent including a com.oculus.horizon CallerIdentity to an arbitrary application registering for com.oculus.systemactivities.SCREENSHOT via a broadcast receiver. That would allow the application to impersonate the com.oculus.horizon package towards any endpoint within the OS that uses CallerIdentity authentication.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92172"
    },
    {
      "rank": 635,
      "cve_id": "CVE-2026-92173",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Meta Platforms, Inc",
      "product": "Meta Horizon OS",
      "cwe": null,
      "title": "Prior to v74.0.0.878.1682 of Meta Horizon OS, MediaSyncJobReceiver could be induced to send a privileged PendingIntent including a com.oculus.vrshell CallerIdentity to an arbitrary application listening via NotificationListenerService. That would allow the application to impersonate the com.oculus.vrshell package, as well as packages signed with the same key, towards any endpoint within the OS that uses CallerIdentity authentication.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92173"
    },
    {
      "rank": 636,
      "cve_id": "CVE-2026-103500",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Thunderbird",
      "cwe": null,
      "title": "Heap buffer overflow opening large email",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103500"
    }
  ],
  "transactions": [
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-76504",
      "detail": "ADDED TO KEV — CVE-2026-76504 (Cisco Catalyst SD-WAN Manager). Remediation due October 3, 2026."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2016-20097",
      "detail": "EXPLOIT PUBLISHED — CVE-2016-20097 (Weaver Network Co., Ltd. E-cology 8.0). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2022-50997",
      "detail": "EXPLOIT PUBLISHED — CVE-2022-50997 (Weaver Network Co., Ltd. E-cology 9.0). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2023-52355",
      "detail": "EXPLOIT PUBLISHED — CVE-2023-52355 (libtiff). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-15612",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-15612 (Wazuh Provisioning Scripts (Agent Build Environment)). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-50343",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-50343. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-100306",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-100306 (TDuckCloud tduck-survey-form). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-100744",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-100744 (coollabsio Coolify). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-100840",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-100840 (Project-MONAI MONAI). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-100842",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-100842 (Project-MONAI MONAI). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-100843",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-100843 (Project-MONAI MONAI). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-100844",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-100844 (Project-MONAI MONAI). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-100845",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-100845 (Project-MONAI MONAI). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-100846",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-100846 (Project-MONAI MONAI). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-100873",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-100873 (mathurvishal CloudClassroom-PHP-Project). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-100876",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-100876 (mathurvishal CloudClassroom-PHP-Project). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-100879",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-100879 (zhistaredu StarTraining). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-100882",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-100882 (Krayin laravel-crm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-100885",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-100885 (Krayin laravel-crm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-100888",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-100888 (Trusted Domain Project OpenDKIM). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-102621",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-102621 (Freedesktop Poppler). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-102771",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-102771 (Naichen ThinkCMF). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48864",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48864 (Red Hat Enterprise Linux 10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-49976",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-49976 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55694",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55694 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55703",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55703 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58010",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58010 (GNOME GLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58012",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58012 (GNOME GLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58013",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58013 (GNOME GLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58014",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58014 (GNOME GLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58015",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58015 (GNOME GLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58016",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58016 (GNOME GLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58380",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58380 (Red Hat Enterprise Linux 8). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58384",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58384 (Red Hat Enterprise Linux 9). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59090",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59090 (gimp). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59095",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59095 (lobehub). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-61807",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-61807 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-66758",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-66758 (GNOME GIMP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76208",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76208 (thorsten phpMyFAQ). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76844",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76844 (zlib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-80428",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-80428 (ILIAS-eLearning e.V. ILIAS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-93353",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-93353 (9001 copyparty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94214",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94214 (ST Engineering iDirect Evolution). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94216",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94216 (ST Engineering iDirect Evolution). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-95276",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-95276 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-95282",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-95282 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-95287",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-95287 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-95289",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-95289 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-95298",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-95298 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-95345",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-95345 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-95346",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-95346 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-95350",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-95350 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-95357",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-95357 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-95359",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-95359 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-95371",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-95371 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-97064",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-97064 (yzcheng90 X-SpringBoot). Public exploit reference added."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2023-39417",
      "detail": "RESCORED — CVE-2023-39417 (Red Hat Advanced Cluster Security 4.2). CVSS 7.5 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21042",
      "detail": "RESCORED — CVE-2025-21042 (Samsung Mobile Devices). CVSS 8.8 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-53844",
      "detail": "RESCORED — CVE-2025-53844 (Fortinet FortiOS). CVSS 8.3 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-66376",
      "detail": "RESCORED — CVE-2025-66376 (Zimbra Collaboration). CVSS 7.2 → 6.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-102793",
      "detail": "RESCORED — CVE-2026-102793 (Ziroom ZHOME A0101). CVSS 9.4 → 8.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-102794",
      "detail": "RESCORED — CVE-2026-102794 (Ziroom ZHOME A0101). CVSS 9.4 → 8.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-10841",
      "detail": "RESCORED — CVE-2026-10841 (IBM CICS TX Advanced). CVSS 4.2 → 4.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-42169",
      "detail": "RESCORED — CVE-2026-42169 (Red Hat Enterprise Linux 9). CVSS 7.3 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50550",
      "detail": "RESCORED — CVE-2026-50550 (grokability snipe-it). CVSS 5.8 → 6.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-59328",
      "detail": "RESCORED — CVE-2026-59328 (Spring Tools for Eclipse). CVSS 4.2 → 5.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-6384",
      "detail": "RESCORED — CVE-2026-6384 (Red Hat Enterprise Linux 6). CVSS 7.3 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-81352",
      "detail": "RESCORED — CVE-2026-81352 (Microsoft Web Media Extensions). CVSS 9.8 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-86105",
      "detail": "RESCORED — CVE-2026-86105 (WatchGuard Fireware OS). CVSS 5.3 → 6 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-93353",
      "detail": "RESCORED — CVE-2026-93353 (9001 copyparty). CVSS 6 → 2.3 (NVD)."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2017-20051",
      "detail": "REJECTED — CVE-2017-20051 (InnoSetup Installer). Record withdrawn by the CNA."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2025-68195",
      "detail": "REJECTED — CVE-2025-68195 (Linux). Record withdrawn by the CNA."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2026-13087",
      "detail": "REJECTED — CVE-2026-13087 (Red Hat Enterprise Linux 10). Record withdrawn by the CNA."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2026-94684",
      "detail": "REJECTED — CVE-2026-94684 (oceanwp Ocean Extra). Record withdrawn by the CNA."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-65488",
      "detail": "PATCH SHIPPED — CVE-2026-65488 (LA-Studio Element Kit for Elementor). Fixed in LA-Studio Element Kit for Elementor 1.6.3."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-65489",
      "detail": "PATCH SHIPPED — CVE-2026-65489 (LA-Studio Element Kit for Elementor). Fixed in LA-Studio Element Kit for Elementor 1.6.3."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-76561",
      "detail": "PATCH SHIPPED — CVE-2026-76561 (Red Hat Enterprise Linux 10). Fixed in Red Hat Enterprise Linux 10 0:11.9.0-5.el10_2."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-80110",
      "detail": "PATCH SHIPPED — CVE-2026-80110 (Red Hat Enterprise Linux 10). Fixed in Red Hat Enterprise Linux 10 0:11.9.0-5.el10_2."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-84268",
      "detail": "PATCH SHIPPED — CVE-2026-84268 (GNOME gvfs). Fixed in Red Hat Enterprise Linux 10 0:1.54.4-4.el10_2.1."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-88924",
      "detail": "PATCH SHIPPED — CVE-2026-88924 (GNOME gvfs). Fixed in Red Hat Enterprise Linux 10 0:1.54.4-4.el10_2.1."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
