{
  "day": "2026-10-01",
  "boundary": "UTC calendar day",
  "published_count": 395,
  "by_severity": {
    "CRITICAL": 41,
    "HIGH": 166,
    "MEDIUM": 144,
    "LOW": 24
  },
  "kev_count": 1,
  "exploit_reference_count": 1,
  "awaiting_enrichment_count": 20,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-104286",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": true,
      "kev_due_at": "2026-10-04",
      "vendor": "Fortinet",
      "product": "FortiMail",
      "cwe": "CWE-22",
      "title": "An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104286"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-55393",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Teledyne FLIR",
      "product": "Aware2",
      "cwe": "CWE-22",
      "title": "Local File Inclusion in Teledyne FLIR Robots running Aware2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55393"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-101148",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "BackupSheep WordPress Backup Plugin",
      "cwe": "CWE-73",
      "title": "BackupSheep <= 1.8 - Unauthenticated Arbitrary File Deletion and Backup Exfiltration via Empty Integration Key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101148"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-79901",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fortra",
      "product": "BoKS Manager boks-server",
      "cwe": "CWE-338",
      "title": "Predictable Active Directory service-account passwords in BoKS Manager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79901"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-96658",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Satellite 6.16 for RHEL 8",
      "cwe": "CWE-94",
      "title": "Foreman: safemode bypass leading to rce",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96658"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-12627",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fortra",
      "product": "Fortra's Core Privileged Access Manager (BoKS)",
      "cwe": "CWE-121",
      "title": "Fortra's Core Privileged Access Manager (BoKS) autoregistration stack buffer overflow vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12627"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-15989",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebRehab",
      "product": "Super Forms – Drag & Drop Form Builder",
      "cwe": "CWE-269",
      "title": "Super Forms <= 6.3.316 - Unauthenticated Privilege Escalation via 'role' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15989"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-56154",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache HTTP Server",
      "cwe": "CWE-416",
      "title": "Apache HTTP Server: mod_rewrite use-after-free via %{LA-U:HTTP:...}",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56154"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-57941",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache HTTP Server",
      "cwe": "CWE-416",
      "title": "Apache HTTP Server: mod_http2 use-after-free / wild write via shared session->bbtmp re-entrancy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57941"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-59797",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache HTTP Server",
      "cwe": "CWE-269",
      "title": "Apache HTTP Server: mod_ssl SSLRequire allows .htaccess ap_expr file-function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59797"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-75957",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "superdav42",
      "product": "Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform",
      "cwe": "CWE-287",
      "title": "Ultimate Multisite <= 2.15.0 - Unauthenticated Authentication Bypass via 'checkout_form' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75957"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-103752",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Paul Ryan",
      "product": "Authorizer",
      "cwe": "CWE-266",
      "title": "WordPress Authorizer plugin <= 3.15.3 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103752"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-56662",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GetSimpleCMS-CE",
      "product": "GetSimpleCMS-CE",
      "cwe": "CWE-352",
      "title": "GetSimple CMS: Missing CSRF protection in UpdateCE allows forging a privileged server-side update request",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56662"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-14157",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ASUS",
      "product": "Router",
      "cwe": "CWE-134",
      "title": "Use of an Externally Controlled Format String in the ASUS Router modules allow a remote authenticated user to execute arbitrary commands via a crafted file uploaded through the web management interface.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14157"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-14984",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Teledyne FLIR",
      "product": "Aware2",
      "cwe": "CWE-319",
      "title": "Cleartext HTTP for Control Traffic in Teledyne FLIR Robots running Aware2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14984"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-18397",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Thales",
      "product": "SConnect",
      "cwe": "CWE-130",
      "title": "SConnect: Native Host Unauthenticated Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18397"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-55395",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Teledyne FLIR",
      "product": "Aware2",
      "cwe": "CWE-798",
      "title": "Hardcoded Passwords in Teledyne FLIR Robots running Aware2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55395"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-94620",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "foundation50",
      "product": "classroom50",
      "cwe": "CWE-22",
      "title": "Classroom 50 vulnerable to arbitrary file overwrite on the teacher's machine via symlink in a student repo (gh teacher download)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94620"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2025-41753",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WAGO",
      "product": "0751-9x01",
      "cwe": "CWE-22",
      "title": "Path traversal in dynamically created BACnet File Objects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-41753"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-13043",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Endpoint Security",
      "cwe": "CWE-306",
      "title": "WatchGuard Endpoint Security Missing Authentication in Kernel Memory Access Driver Allows Arbitrary Kernel Memory Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13043"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-62071",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nickboss",
      "product": "WordPress File Upload",
      "cwe": "CWE-89",
      "title": "WordPress WordPress File Upload plugin <= 5.1.10 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62071"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-71449",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Johnson Controls",
      "product": "EasyIO FS32",
      "cwe": "CWE-321",
      "title": ": Use of Hard-coded Cryptographic Key vulnerability in Johnson Controls EasyIO FS32 allows : Retrieve Embedded Sensitive Data. This issue affects EasyIO FS32: before 3.0b63.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71449"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-76142",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Genians, Inc",
      "product": "Genian NAC 5.0.75 LTS Release",
      "cwe": "CWE-284",
      "title": "Genians, Inc. Genian NAC/ZTNA Improper Access Control on the Internal Interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76142"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-82824",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hitachi Industrial Equipment Systems",
      "product": "Hitachi Coding Software Suite",
      "cwe": "CWE-35",
      "title": "Path traversal may allow arbitrary files to be viewed, created, modified, or deleted",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82824"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-82825",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hitachi Industrial Equipment Systems",
      "product": "Hitachi Coding Software Suite",
      "cwe": "CWE-306",
      "title": "Missing proper authentication for critical APIs may allow sensitive information to be obtained or modified, or unauthorized operations to be performed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82825"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-82827",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hitachi Industrial Equipment Systems",
      "product": "Hitachi Coding Software Suite",
      "cwe": "CWE-321",
      "title": "A hard-coded JWT signing secret key may allow administrative functions to be abused using fraudulently generated Bearer tokens",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82827"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-82829",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hitachi Industrial Equipment Systems",
      "product": "Hitachi Coding Software Suite",
      "cwe": "CWE-912",
      "title": "Hidden accounts or hard-coded credentials may permit unauthorized access without the legitimate authentication process",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82829"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-103244",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sgoudelis",
      "product": "ground-station",
      "cwe": "CWE-306",
      "title": "ground-station before 0.8.0 Authentication Bypass via setup.restore",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103244"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-103264",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fleetdm",
      "product": "fleet",
      "cwe": "CWE-287",
      "title": "Fleet before 4.87.0 Authentication Bypass via Device Identifiers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103264"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-103655",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-294",
      "title": "MISP TOTP Code Replay Allows Duplicate Authentication Within Validity Period",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103655"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-103764",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kvcache-ai",
      "product": "Mooncake",
      "cwe": "CWE-822",
      "title": "Mooncake transfer engine before 0.3.13 Unauthenticated Arbitrary Memory Read/Write via TCP Transport",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103764"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-103922",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ionic-team",
      "product": "capacitor",
      "cwe": "CWE-346",
      "title": "Capacitor Android and iOS: remote content can be loaded at the app origin via the internal HTTP proxy path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103922"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-102628",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eummena",
      "product": "Cadmos LTI",
      "cwe": "CWE-215",
      "title": "Cadmos LTI exposure of sensitive information via debug mode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102628"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-53953",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GetSimpleCMS-CE",
      "product": "GetSimpleCMS-CE",
      "cwe": "CWE-338",
      "title": "GetSimple CMS: Predictable Password Reset Password Allows Administrator Account Takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53953"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-55083",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dhis2",
      "product": "dhis2-core",
      "cwe": "CWE-502",
      "title": "DHIS2: Unsafe Java Deserialization - Remote Code Execution (RCE)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55083"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-56660",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GetSimpleCMS-CE",
      "product": "GetSimpleCMS-CE",
      "cwe": "CWE-352",
      "title": "GetSimple CMS: CSRF, SSRF, and Unrestricted Zip Extraction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56660"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-79898",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fortra",
      "product": "BoKS Manager",
      "cwe": "CWE-78",
      "title": "Fortra BoKS Manager crlserver command injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79898"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-92966",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "latepoint",
      "product": "Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress",
      "cwe": "CWE-94",
      "title": "Appointment Booking Plugin <= 5.7.0 - Unauthenticated Arbitrary Shortcode Execution via First/Last Name Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92966"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-96659",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Satellite 6.16 for RHEL 8",
      "cwe": "CWE-267",
      "title": "Foreman: excessive permissions for viewer role on preview",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96659"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-86345",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Directory Server 11",
      "cwe": "CWE-923",
      "title": "389-ds-base: 389-ds-base: starttls plaintext-buffer retention allows on-path attacker to forge an ldap client's authentication result",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86345"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-102667",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joyland",
      "product": "Joyland.ai",
      "cwe": "CWE-749",
      "title": "Joyland AI WebView command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102667"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-13313",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ASUS",
      "product": "Router",
      "cwe": "CWE-489",
      "title": "An Active Debug Code vulnerability in certain ASUS router models allows a remote authenticated user, via a crafted HTTP request, to bypass security mechanisms and enable the Telnet service, thereby executing arbitrary commands with root privileges and potentially affecting other devices connected to the router. Refer to the ' Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13313"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-12405",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Satellite 6.16 for RHEL 8",
      "cwe": "CWE-78",
      "title": "Rubygem-foreman_remote_execution: command injection in job invocations via effective_user parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12405"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-19807",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bytecorestack",
      "product": "ByteCoreStack – MCP Connector for AI Tools",
      "cwe": "CWE-269",
      "title": "ByteCoreStack <= 1.2.3 - Authenticated (Subscriber+) Privilege Escalation via wp_update_user_meta MCP Tool",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19807"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-66246",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "iControl",
      "cwe": "CWE-250",
      "title": "HCL iControl is affected by multiple security vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66246"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-70650",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GetSimpleCMS-CE",
      "product": "GetSimpleCMS-CE",
      "cwe": "CWE-79",
      "title": "GetSimple CMS: Authenticated Stored XSS in backup viewer (backup-edit.php) via output decoding of page meta fields and content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70650"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-80275",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Comelit Group S.p.A.",
      "product": "1456B Multi-User Gateway",
      "cwe": "CWE-425",
      "title": "Comelit 1456B gateway allows low priviledge user to overwrite installer password via unauthorized endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80275"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-93546",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache HTTP Server",
      "cwe": "CWE-190",
      "title": "Apache HTTP Server: mod_dav_fs namespace overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93546"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-95687",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpclever",
      "product": "WPC Shop as a Customer for WooCommerce",
      "cwe": "CWE-269",
      "title": "WPC Shop as a Customer for WooCommerce <= 2.0.0 - Authenticated (Subscriber+) Privilege Escalation via Missing Role Check on Target User to wpcsa_login AJAX Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95687"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-97284",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Icegram",
      "product": "Icegram",
      "cwe": "CWE-502",
      "title": "WordPress Icegram plugin <= 3.1.31 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97284"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-101147",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Featured Image from URL (FIFU)",
      "cwe": "CWE-352",
      "title": "Featured Image from URL (FIFU) Free & Premium - Administrator Account Creation via CSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101147"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-103068",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ByteCore Stack",
      "product": "ByteCoreStack &#8211; MCP Connector for AI Tools",
      "cwe": "CWE-266",
      "title": "WordPress ByteCoreStack – MCP Connector for AI Tools plugin <= 1.2.2 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103068"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-103484",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "pgvector",
      "cwe": "CWE-787",
      "title": "pgvector buffer overflow in IVFFlat index build",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103484"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-103765",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kvcache-ai",
      "product": "Mooncake",
      "cwe": "CWE-306",
      "title": "Mooncake through 0.3.13.post1 Missing Authentication in HTTP Metadata Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103765"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-104018",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wind River Systems Inc",
      "product": "VxWorks 7",
      "cwe": "CWE-269",
      "title": "VxWorks 7 improper privilege management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104018"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-104051",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HaschekSolutions",
      "product": "pictshare",
      "cwe": "CWE-522",
      "title": "PictShare < 3.7.1 Sensitive Information Disclosure via info API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104051"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2024-58388",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sharp Corporation",
      "product": "Multiple Multifunction Printers",
      "cwe": "CWE-22",
      "title": "Sharp Multifunction Printers Local File Inclusion via installed_emanual_down.html",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-58388"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-19253",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Cache Enabler",
      "cwe": "CWE-73",
      "title": "Cache Enabler < 1.8.17 - Unauthenticated Arbitrary File and Directory Deletion via cache_enabler_clear_page_cache_by_url",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19253"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-54049",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sakaiproject",
      "product": "sakai",
      "cwe": "CWE-79",
      "title": "Sakai Conversations has a Stored XSS Issue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54049"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-55230",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "givanz",
      "product": "Vvveb",
      "cwe": "CWE-79",
      "title": "Vvveb: Stored XSS in Vvveb via sanitizeHTML() filter bypass using a quoted greater-than character",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55230"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-71542",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GetSimpleCMS-CE",
      "product": "GetSimpleCMS-CE",
      "cwe": "CWE-79",
      "title": "GetSimple CMS: Stored Cross-Site Scripting (XSS) via the \"title\" parameter in admin/components.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71542"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-82826",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hitachi Industrial Equipment Systems",
      "product": "Hitachi Coding Software Suite",
      "cwe": "CWE-319",
      "title": "Authentication information or sensitive data may be intercepted in transit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82826"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-82828",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hitachi Industrial Equipment Systems",
      "product": "Hitachi Coding Software Suite",
      "cwe": "CWE-863",
      "title": "Improper authorization may allow a general user to perform operations equivalent to those available with administrator privileges",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82828"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-102369",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Tapo C200 v5",
      "cwe": "CWE-287",
      "title": "Unauthenticated Remote Code Execution via MacTool Command Injection in TP-Link Tapo C120 & C200",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102369"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-103262",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tornadoweb",
      "product": "tornado",
      "cwe": "CWE-409",
      "title": "Tornado before 6.5.9 Denial of Service via CurlAsyncHTTPClient",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103262"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-103268",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-862",
      "title": "Ghost 1.0.0 before 6.62.0 Suspension Bypass via Password Reset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103268"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-103271",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-863",
      "title": "Ghost 4.0.0 before 6.63.0 Restricted Content Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103271"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-103272",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-203",
      "title": "Ghost 2.10.0 before 6.63.0 Staff Enumeration via Content API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103272"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-103761",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kvcache-ai",
      "product": "Mooncake",
      "cwe": "CWE-770",
      "title": "Mooncake transfer engine through 0.3.13.post1 Memory Exhaustion via Unbounded Notify Queue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103761"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-104020",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Amazon",
      "product": "ion-python",
      "cwe": "CWE-674",
      "title": "Uncontrolled recursion in the Ion reader in Amazon Ion Python",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104020"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-104057",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "akhilrex",
      "product": "podgrab",
      "cwe": "CWE-362",
      "title": "Podgrab Unauthenticated DoS via Concurrent Map Access in WebSocket Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104057"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-64949",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pandora FMS",
      "product": "Pandora FMS",
      "cwe": "CWE-434",
      "title": "Unrestricted File Upload Leading to Remote Code Execution in Admin Tools File Manager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64949"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-88789",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Camel Quarkus",
      "cwe": "CWE-611",
      "title": "Apache Camel Quarkus: Camel Quarkus: Forced Xalan TransformerFactory drops upstream external-DTD/stylesheet hardening",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88789"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-89296",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Pro Like Button",
      "cwe": "CWE-89",
      "title": "Pro Like Button < 2.0 - Unauthenticated SQLi via 'postid' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89296"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-95588",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AcyMailing Newsletter Team",
      "product": "AcyMailing SMTP Newsletter",
      "cwe": "CWE-22",
      "title": "WordPress AcyMailing SMTP Newsletter plugin <= 11.0.5 - Arbitrary File Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95588"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-101888",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Codexonics",
      "product": "Prime Mover",
      "cwe": "CWE-22",
      "title": "Prime Mover < 2.2.1 Zip Slip Path Traversal File Write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101888"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-103277",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-79",
      "title": "Ghost 2.5.0 before 6.34.0 Untrusted Script Execution via oEmbed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103277"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-103283",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-613",
      "title": "Ghost 6.20.0 before 6.57.1 Authentication Bypass via Session Handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103283"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-103292",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-79",
      "title": "Ghost 0.5.3 before 6.50.0 Cross-Site Scripting via ghost_head",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103292"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-103758",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "obot-platform",
      "product": "obot",
      "cwe": "CWE-863",
      "title": "Obot 0.21.1 through 0.24.1 Authorization Bypass via /mcp-connect-composite/ Route",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103758"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-103766",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MacWarrior",
      "product": "clipbucket-v5",
      "cwe": "CWE-89",
      "title": "ClipBucket v5 through 5.5.3-#197 SQL Injection via ads_manager.php delete Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103766"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-55396",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Teledyne FLIR",
      "product": "Aware2",
      "cwe": "CWE-319",
      "title": "Unencrypted UDP Control Traffic in Teledyne FLIR Robots running Aware2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55396"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-102294",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link System Inc.",
      "product": "TL-WR841N v14",
      "cwe": "CWE-78",
      "title": "Authenticated OS Command Injection in TL-WR841N IPv6 WAN Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102294"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-102379",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VillaTheme",
      "product": "BuildKit – Product Builder for WooCommerce – Custom PC Builder",
      "cwe": "CWE-89",
      "title": "WordPress BuildKit – Product Builder for WooCommerce – Custom PC Builder plugin <= 1.0.28 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102379"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-103259",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-863",
      "title": "n8n before 2.39.6 and 2.40.x before 2.40.1 Session Token Leak via Dynamic Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103259"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-103278",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-23",
      "title": "Ghost 5.8.0 before 6.34.0 Staff Account Takeover via Admin iframe",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103278"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-103286",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-266",
      "title": "Ghost 2.21.0 before 6.56.0 Privilege Escalation via Notifications",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103286"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-103338",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unlimited Elements",
      "product": "Unlimited Elements For Elementor (Free Widgets, Addons, Templates)",
      "cwe": "CWE-89",
      "title": "WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.20 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103338"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-64950",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pandora FMS",
      "product": "Pandora FMS",
      "cwe": "CWE-79",
      "title": "Stored Cross-Site Scripting via Directory Name in File Manager Create Directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64950"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-73975",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "4TUResearchData",
      "product": "djehuty",
      "cwe": "CWE-943",
      "title": "djehuty: Authenticated SPARQL injection in session editing allows writing arbitrary RDF triples",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73975"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-76146",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Genians, Inc",
      "product": "Genian SSL PNS (xenics_auther)",
      "cwe": "CWE-78",
      "title": "Genians, Inc Genian SSL PNS OS Command Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76146"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-102514",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PeaZip",
      "product": "PeaZip",
      "cwe": "CWE-787",
      "title": "Out-of-bounds write in PeaZip PEA extractor allows code execution via a crafted .pea archive",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102514"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-101322",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse BaSyx AAS Web UI",
      "cwe": "CWE-201",
      "title": "In Eclipse BaSyx AAS Web UI versions v2-241220 through releases before v2-260924, the shared request handler attached the selected infrastructure's `Authorization` header to outgoing requests without checking the destination origin. In deployments using authentication, an attacker could induce a user to open a crafted Web UI link whose `aas` or `path` query parameter points to an attacker-controlled endpoint. The user's browser would then send the configured Basic Authentication credentials, Bearer token, or an available OAuth2 access token to that endpoint. The attacker could reuse the disclosed credential to access protected AAS services with the victim's privileges. The issue is fixed in v2-260924.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101322"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-103246",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-639",
      "title": "n8n before 2.39.6 and 2.40.x before 2.40.1 Credential Disclosure via Node-Tool Introspection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103246"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-103757",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Budibase",
      "product": "budibase",
      "cwe": "CWE-918",
      "title": "Budibase before 3.41.0 SSRF via uploadUrl in AI Table Generation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103757"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2023-54404",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "colinhacks",
      "product": "zod",
      "cwe": "CWE-770",
      "title": "Zod 4.6.5 Uncontrolled Resource Consumption via Array Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-54404"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-12540",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Satellite 6.16 for RHEL 8",
      "cwe": "CWE-78",
      "title": "Foreman: command injection in foreman-rake errors:fetch_log via request_id parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12540"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-12541",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Satellite 6.16 for RHEL 8",
      "cwe": "CWE-78",
      "title": "Foreman: command injection in foreman-rake database tasks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12541"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-94250",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache APISIX",
      "cwe": "CWE-770",
      "title": "Apache APISIX: Batch response aggregation can exhaust worker memory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94250"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-96780",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patorjk",
      "product": "figlet.js",
      "cwe": "CWE-835",
      "title": "figlet is vulnerable to denial of service via unbounded loop when whitespaceBreak is used with a small width",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96780"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-103263",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tornadoweb",
      "product": "tornado",
      "cwe": "CWE-59",
      "title": "Tornado before 6.5.9 StaticFileHandler Path Traversal via Symlink",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103263"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-103760",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kvcache-ai",
      "product": "Mooncake",
      "cwe": "CWE-400",
      "title": "Mooncake transfer engine through 0.3.13.post1 Denial of Service via P2P Handshake Daemon Response Write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103760"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-104356",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HaschekSolutions",
      "product": "pictshare",
      "cwe": "CWE-338",
      "title": "PictShare < 3.7.1 Predictable Delete Code via rand()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104356"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-14316",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fortra",
      "product": "Core Privileged Access Manager (BoKS)",
      "cwe": "CWE-122",
      "title": "Heap buffer overflow in boks_sshd revoked-key error handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14316"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-15983",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebRehab",
      "product": "Super Forms – Drag & Drop Form Builder",
      "cwe": "CWE-73",
      "title": "Super Forms <= 6.3.316 - Authenticated (Subscriber+) Arbitrary File/Directory Deletion via 'subdir' / 'path' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15983"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-73636",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache HTTP Server",
      "cwe": "CWE-294",
      "title": "Apache HTTP Server: mod_auth_digest one-time-nonce replay attack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73636"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-103257",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-22",
      "title": "n8n before 1.123.80, 2.39.6, and 2.40.1 Path Traversal via n8n Node",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103257"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-103493",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-79",
      "title": "In JetBrains YouTrack before 2026.2.19422 stored XSS via Mermaid and LaTeX content was possible",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103493"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-103067",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Memberful",
      "product": "Memberful - Membership Plugin",
      "cwe": "CWE-352",
      "title": "WordPress Memberful - Membership Plugin plugin <= 1.81.0 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103067"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-79899",
      "cvss_base": 7.9,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fortra",
      "product": "BoKS Manager",
      "cwe": "CWE-377",
      "title": "Fortra BoKS Manager bccgethostcert insecure temporary file vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79899"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-8618",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Deco M9 Plus V2",
      "cwe": "CWE-121",
      "title": "Pre-Authentication Stack-based Buffer Overflow Remote Code Execution in TDDPv2 Subtype 0x91 on Deco M9 Plus",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8618"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-12544",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Satellite 6.16 for RHEL 8",
      "cwe": "CWE-502",
      "title": "Foreman: ssti and insecure deserialization in foreman-rake configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12544"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-84682",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Archer AX90 v1",
      "cwe": "CWE-78",
      "title": "TDDPv2 setProductVer Command Injection in Archer AX90",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84682"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-103431",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "collectl",
      "cwe": "CWE-150",
      "title": "Collectl: collectl: colmux does not sanitize ansi/vt100 terminal escape sequences in data received from remote collectl instances",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103431"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2025-71427",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GongRzhe",
      "product": "Office-PowerPoint-MCP-Server",
      "cwe": "CWE-22",
      "title": "Office-PowerPoint-MCP-Server through 2.0.7 Path Traversal via save_presentation and manage_image",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71427"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-55232",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "givanz",
      "product": "Vvveb",
      "cwe": "CWE-918",
      "title": "Vvveb: Server-side request forgery in Vvveb via IPv6 bypass of validateUrl() in editor oEmbed proxy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55232"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-62059",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ultimate Member",
      "product": "Ultimate Member",
      "cwe": "CWE-89",
      "title": "WordPress Ultimate Member plugin <= 2.13.1 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62059"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-62060",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "captivateaudio",
      "product": "Captivate Sync",
      "cwe": "CWE-89",
      "title": "WordPress Captivate Sync plugin <= 3.3.2 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62060"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-97277",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apps Mav",
      "product": "Social Boost",
      "cwe": "CWE-862",
      "title": "WordPress Social Boost plugin <= 3.6.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97277"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-97297",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apps Mav",
      "product": "Gratisfaction",
      "cwe": "CWE-862",
      "title": "WordPress Gratisfaction plugin <= 4.6.3 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97297"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-103279",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-613",
      "title": "Ghost 3.10.0 before 6.34.0 Session Invalidation Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103279"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-103651",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-287",
      "title": "MISP HOTP Token Replay via Stale Session-Cached Counter Allows Second-Factor Authentication Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103651"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-12423",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Satellite 6.16 for RHEL 8",
      "cwe": "CWE-306",
      "title": "Foreman: unauthenticated information disclosure via provisioning token validation flaw",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12423"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-46729",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache HTTP Server",
      "cwe": "CWE-476",
      "title": "Apache HTTP Server: mod_heartmonitor denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46729"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-47360",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache HTTP Server",
      "cwe": "CWE-200",
      "title": "Apache HTTP Server: mod_session: Session cookie not removed during internal redirect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47360"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-48005",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache HTTP Server",
      "cwe": "CWE-306",
      "title": "Apache HTTP Server: mod_auth_digest reauthentication attack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48005"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-56153",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache HTTP Server",
      "cwe": "CWE-787",
      "title": "Apache HTTP Server: mod_charset_lite: Heap overflow in finish_partial_char",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56153"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-56449",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache HTTP Server",
      "cwe": "CWE-787",
      "title": "Apache HTTP Server: mod_proxy_html: crash in dump_content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56449"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-56661",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GetSimpleCMS-CE",
      "product": "GetSimpleCMS-CE",
      "cwe": "CWE-918",
      "title": "GetSimple CMS: Server-Side Request Forgery in the UpdateCE update endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56661"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-59685",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache HTTP Server",
      "cwe": "CWE-787",
      "title": "Apache HTTP Server: Out-of-Bounds Write in ap_directory_walk() Canonical-Name Rewrite on CASE_BLIND_FILESYSTEM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59685"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-62073",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themeisle",
      "product": "WP Full Stripe Free",
      "cwe": "CWE-862",
      "title": "WordPress WP Full Stripe Free plugin <= 8.5.6 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62073"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-63045",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache HTTP Server",
      "cwe": "CWE-284",
      "title": "Apache HTTP Server: mod_proxy_ftp PASV address handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63045"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-63292",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache HTTP Server",
      "cwe": "CWE-121",
      "title": "Apache HTTP Server: mod_vhost_alias stack overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63292"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-63686",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache HTTP Server",
      "cwe": "CWE-476",
      "title": "Apache HTTP Server: mod_xml2enc crash on charset conversion failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63686"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-63718",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache HTTP Server",
      "cwe": "CWE-444",
      "title": "Apache HTTP Server: mod_proxy_uwsgi Transfer-Encoding response smuggling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63718"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-64947",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pandora FMS",
      "product": "Pandora FMS",
      "cwe": "CWE-352",
      "title": "CSRF Bypass Leading to Remote Code Execution via Unrestricted File Upload in Plugin File Manager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64947"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-68495",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FasterXML",
      "product": "jackson-dataformats-binary",
      "cwe": "CWE-400",
      "title": "jackson-dataformats-binary: CBOR parser does not enforce StreamReadConstraints.maxNameLength, enabling memory-exhaustion denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68495"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-68496",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FasterXML",
      "product": "jackson-dataformats-binary",
      "cwe": "CWE-400",
      "title": "jackson-dataformats-binary: Smile parser does not enforce StreamReadConstraints.maxNameLength, enabling memory-exhaustion denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68496"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-76145",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Genians, Inc",
      "product": "Genian SSL PNS (frodo-core)",
      "cwe": "CWE-269",
      "title": "Genians, Inc Genian SSL PNS Improper Privilege Management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76145"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-79896",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fortra",
      "product": "BoKS Manager",
      "cwe": "CWE-125",
      "title": "Fortra BoKS Manager boks_portmux TLS ClientHello out-of-bounds read vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79896"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-80276",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Comelit Group S.p.A.",
      "product": "1456B Multi-User Gateway",
      "cwe": "CWE-306",
      "title": "Comelit 1456B gateway exposes remote configuration password via unauthenticated management interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80276"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-81739",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Paytm Payment Gateway",
      "cwe": "CWE-79",
      "title": "Paytm Payment Gateway < 2.8.9 - Unauthenticated Stored XSS via Payment Callback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81739"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-81809",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Paytm Payment Gateway",
      "cwe": "CWE-89",
      "title": "Paytm Payment Gateway < 2.8.9 - Unauthenticated SQLi via Payment Callback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81809"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-86344",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Directory Server 11",
      "cwe": "CWE-400",
      "title": "389-ds-base: 389-ds-base: unauthenticated worker-thread-pool exhaustion via completed-operation-then-incomplete-pdu connection requeue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86344"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-92245",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "croixhaug",
      "product": "Simply Schedule Appointments",
      "cwe": "CWE-862",
      "title": "Simply Schedule Appointments <= 1.6.12.32 - Missing Authorization to Unauthenticated Sensitive Information Exposure and Arbitrary Appointment Deletion via 'recursive' Parameter on the appointment_types REST Endpoint via Public Nonce",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92245"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-93882",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thimpress",
      "product": "LearnPress – WordPress LMS Plugin for Create and Sell Online Courses",
      "cwe": "CWE-639",
      "title": "LearnPress <= 4.4.8 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'item_id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93882"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-96255",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Payments for Hubtel",
      "cwe": "CWE-200",
      "title": "Payments for Hubtel < 1.0.2 - Unauthenticated Payment Gateway Credentials Disclosure via Debug Log",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96255"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-100514",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pete Nelson",
      "product": "REST API Log",
      "cwe": "CWE-639",
      "title": "WordPress REST API Log plugin <= 1.7.2 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100514"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-100517",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VillaTheme",
      "product": "Photo Reviews for WooCommerce",
      "cwe": "CWE-639",
      "title": "WordPress Photo Reviews for WooCommerce plugin <= 1.2.30 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100517"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-102504",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "Imager",
      "cwe": "CWE-190",
      "title": "Imager versions before 1.037 for Perl exit the process reading a raw image with an out-of-range raw_datachannels value in i_readraw_wiol",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102504"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-103251",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-862",
      "title": "n8n before 1.123.80, 2.39.6, and 2.40.1 Package Install Validation Bypass via PubSub",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103251"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-15911",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "confluent",
      "product": "confluent-kafka",
      "cwe": "CWE-295",
      "title": "Confluent Kafka Python Improper TLS Certificate Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15911"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-64946",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pandora FMS",
      "product": "Pandora FMS",
      "cwe": "CWE-79",
      "title": "CSRF Bypass Leading to Stored Cross-Site Scripting via Unrestricted SVG Upload in File Manager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64946"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-67105",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "HCL BigFix Service Management",
      "cwe": "CWE-319",
      "title": "HCL BigFix Service Management is affected by multiple security vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67105"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-103921",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ardatan",
      "product": "graphql-tools",
      "cwe": "CWE-295",
      "title": "GraphQL Tools: TLS Certificate Validation Disabled in Legacy GraphQL WebSocket Executor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103921"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-64893",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Johnson Controls",
      "product": "EasyIO NEO",
      "cwe": "CWE-319",
      "title": "- Cleartext Transmission of Sensitive Information vulnerability in Johnson Controls EasyIO NEO allows - Man In the Middle Attack. This issue affects EasyIO NEO: before 3.3b25.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64893"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-73637",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache HTTP Server",
      "cwe": "CWE-416",
      "title": "Apache HTTP Server: mod_auth_digest DoS attack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73637"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-76143",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Genians, Inc",
      "product": "Genian SSL PNS (frodo-core)",
      "cwe": "CWE-862",
      "title": "Genians, Inc Genian SSL PNS Multi Factor Authentication Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76143"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-14995",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "optimizingmatters",
      "product": "Autoptimize",
      "cwe": "CWE-79",
      "title": "Autoptimize <= 3.1.15.1 - Unauthenticated Stored Cross-Site Scripting via REQUEST_URI Path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14995"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-34493",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Johnson Controls",
      "product": "EasyIO FS32",
      "cwe": "CWE-1191",
      "title": "- On-Chip Debug Interface vulnerability in Johnson Controls EasyIO FS32 allows Collect Data from Common Resource Locations. This issue affects EasyIO FS32: before 3.3b63.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34493"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-34494",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Johnson Controls",
      "product": "Neo Series MVP2",
      "cwe": "CWE-1191",
      "title": "- On-Chip Debug Interface vulnerability in Johnson Controls Neo Series MVP2 allows Collect Data from Common Resource Locations. This issue affects Neo Series MVP2: before 3.3b63.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34494"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-53964",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "adfinis",
      "product": "document-merge-service",
      "cwe": "CWE-1336",
      "title": "Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53964"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-55231",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "givanz",
      "product": "Vvveb",
      "cwe": "CWE-22",
      "title": "Vvveb: Path traversal in Vvveb via sanitizeFileName() bypass enables arbitrary file read and delete through backup tools",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55231"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-56589",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "HCL BigFix Service Management",
      "cwe": "CWE-79",
      "title": "HCL BigFix Service Management is affected by multiple security vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56589"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-71452",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Johnson Controls",
      "product": "EasyIO FS32",
      "cwe": "CWE-78",
      "title": "- OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows OS Command Injection. This issue affects EasyIO FS32: before 3.0b63.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71452"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-75786",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pandora FMS",
      "product": "Pandora FMS",
      "cwe": "CWE-89",
      "title": "SQL Injection in Grafana Integration Endpoint (query.php)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75786"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-85235",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpmudev",
      "product": "Forminator Forms – Contact Form, Payment Form & Custom Form Builder",
      "cwe": "CWE-79",
      "title": "Forminator Forms <= 1.57.2 - Unauthenticated Stored Cross-Site Scripting via Rich-Text Textarea Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85235"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-85679",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "extendify",
      "product": "Extendify",
      "cwe": "CWE-79",
      "title": "Extendify <= 3.1.6 - Unauthenticated Stored Cross-Site Scripting via 'styles.blocks' Block Type Key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85679"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-92144",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpmudev",
      "product": "Forminator Forms – Contact Form, Payment Form & Custom Form Builder",
      "cwe": "CWE-79",
      "title": "Forminator Forms <= 1.57.2 - Unauthenticated Stored Cross-Site Scripting via 'postdata-1[post-custom]' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92144"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-92244",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpovernight",
      "product": "PDF Invoices & Packing Slips for WooCommerce",
      "cwe": "CWE-79",
      "title": "PDF Invoices & Packing Slips for WooCommerce <= 5.16.1 - Unauthenticated Stored Cross-Site Scripting via Billing First Name / Last Name / Company Fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92244"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-94390",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dotstore",
      "product": "Hide Shipping Method For WooCommerce",
      "cwe": "CWE-502",
      "title": "WordPress Hide Shipping Method For WooCommerce plugin <= 1.5.4 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94390"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-96561",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tigroumeow",
      "product": "AI Engine – The Chatbot, AI Framework & MCP for WordPress",
      "cwe": "CWE-79",
      "title": "AI Engine <= 3.8.0 - Unauthenticated Stored Cross-Site Scripting via 'model_' Parameter → PHP Error-Log Injection → Advisor Indirect Prompt Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96561"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-96573",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "codepeople",
      "product": "Appointment Hour Booking – Booking Calendar",
      "cwe": "CWE-79",
      "title": "Appointment Hour Booking <= 1.5.97 - Unauthenticated Stored DOM-Based Cross-Site Scripting via Booking Form Single-Line Field via Schedule Calendar List Renderer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96573"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-96813",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "10web",
      "product": "Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder",
      "cwe": "CWE-79",
      "title": "Form Maker by 10Web <= 1.15.47 - Unauthenticated Stored Cross-Site Scripting via Mark on Map Longitude/Latitude Fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96813"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-97661",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "scottpaterson",
      "product": "Business Essentials for Contact Form 7",
      "cwe": "CWE-79",
      "title": "Business Essentials for Contact Form 7 <= 1.2.1 - Unauthenticated Stored Cross-Site Scripting via 'gateway' Form Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97661"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-103082",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LA-Studio",
      "product": "LA-Studio Element Kit for Elementor",
      "cwe": "CWE-918",
      "title": "WordPress LA-Studio Element Kit for Elementor plugin <= 1.6.2 - Server Side Request Forgery (SSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103082"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-103490",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-862",
      "title": "In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group links",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103490"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-9032",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Tapo C200 V5",
      "cwe": "CWE-476",
      "title": "Unauthenticated Onboarding Connect NULL Pointer Dereference Denial of Service Vulnerability in TP-Link Tapo C120 & C200",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9032"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-14983",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Teledyne FLIR",
      "product": "Aware2",
      "cwe": "CWE-306",
      "title": "Missing Authentication in Teledyne FLIR Robots running Aware2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14983"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-64948",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pandora FMS",
      "product": "Pandora FMS",
      "cwe": "CWE-639",
      "title": "Missing Authorization in get_module_detail AJAX Endpoint Allows Cross-Group Module Data Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64948"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-71426",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GetSimpleCMS-CE",
      "product": "GetSimpleCMS-CE",
      "cwe": "CWE-22",
      "title": "GetSimple CMS: Authenticated Stored Local File Inclusion (LFI) via page \"template\" field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71426"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-73976",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "4TUResearchData",
      "product": "djehuty",
      "cwe": "CWE-943",
      "title": "djehuty: Unauthenticated SPARQL injection in the search API (`order`, `operator`, `key`)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73976"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-78210",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Octopus Deploy",
      "product": "Octopus Server",
      "cwe": "CWE-863",
      "title": "In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts in an environment without possessing the required authorization.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78210"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-78578",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Tapo C200 v5",
      "cwe": "CWE-306",
      "title": "Unauthenticated do Method Onboarding Connect Allows Wi‑Fi Reconfiguration Denial of Service Vulnerability in TP-Link Tapo C120 & C200",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78578"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-82357",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RT-Labs AB",
      "product": "C-Open",
      "cwe": "CWE-476",
      "title": "RT-Labs AB C-Open CANopen NULL pointer dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82357"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-82358",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RT-Labs AB",
      "product": "C-Open",
      "cwe": "CWE-863",
      "title": "RT-Labs AB C-Open CANopen SDO Server Write Protection Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82358"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-92412",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Five Star Restaurant Reviews",
      "cwe": "CWE-79",
      "title": "Five Star Restaurant Reviews < 2.3.14 - Reflected XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92412"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-96577",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Assisted Installer for Red Hat OpenShift Container Platform 2",
      "cwe": "CWE-306",
      "title": "Oc-mirror__release-4.21: embedded local cache registry listens on all interfaces without authentication, with delete enabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96577"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-97260",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "maxfoundry",
      "product": "MaxGalleria",
      "cwe": "CWE-79",
      "title": "WordPress MaxGalleria plugin <= 6.5.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97260"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-97268",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Premmerce",
      "product": "Premmerce Wishlist for WooCommerce",
      "cwe": "CWE-79",
      "title": "WordPress Premmerce Wishlist for WooCommerce plugin <= 1.1.13 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97268"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-97273",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Premmerce",
      "product": "Premmerce Wishlist for WooCommerce",
      "cwe": "CWE-79",
      "title": "WordPress Premmerce Wishlist for WooCommerce plugin <= 1.1.13 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97273"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-102378",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bPlugins",
      "product": "Parallax Section block",
      "cwe": "CWE-79",
      "title": "WordPress Parallax Section block plugin <= 2.0.4 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102378"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-103248",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-89",
      "title": "n8n before 1.123.80, 2.39.6, and 2.40.1 PostgREST Filter Injection via Supabase",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103248"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-103252",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-639",
      "title": "n8n before 1.123.80, 2.39.6, and 2.40.1 Information Disclosure via Credential Test Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103252"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-103255",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-73",
      "title": "n8n before 1.123.80, 2.39.6, and 2.40.1 Path Traversal and Query Injection via Supabase",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103255"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-103256",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-522",
      "title": "n8n before 2.39.6 and 2.40.x before 2.40.1 Credentials Leak via preAuthentication Hook",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103256"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-103266",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-863",
      "title": "Ghost 5.2.0 before 6.62.0 Unauthenticated Stripe Checkout Account Modification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103266"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-103288",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-639",
      "title": "Ghost 5.9.0 before 6.44.1 Authorization Bypass via Comment Like",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103288"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-103289",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-943",
      "title": "Ghost 5.9.0 before 6.44.1 Authorization Bypass via Comments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103289"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-103488",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-863",
      "title": "In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed authenticated users to add themselves to project teams and access restricted issues",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103488"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-103659",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-285",
      "title": "MISP: Object Distribution ACL Bypass via Event Flattening Exposes Organisation-Only Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103659"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-93495",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ASUS",
      "product": "Motherboard(PRIME Z390-A )",
      "cwe": "CWE-665",
      "title": "Improper initialization in an ASUS certain motherboard allows an physically proximate user to read or write arbitrary memory by inserting a specially crafted device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93495"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-101889",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Codexonics",
      "product": "Prime Mover",
      "cwe": "CWE-22",
      "title": "Prime Mover < 2.2.1 Path Traversal via wprime-config.json",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101889"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-103250",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-943",
      "title": "n8n before 1.123.80, 2.39.6, and 2.40.1 NoSQL Injection via MongoDB Chat Memory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103250"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-103253",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-89",
      "title": "n8n before 1.123.80, 2.39.6, and 2.40.1 SQL Injection via Oracle Database Drop Table",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103253"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-103254",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-22",
      "title": "n8n before 1.123.80, 2.39.6, and 2.40.1 Path Traversal via Resume URL Generation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103254"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-104059",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lektor",
      "product": "lektor",
      "cwe": "CWE-352",
      "title": "Lektor 3.3.14 CSRF via Admin API Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104059"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-97662",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "security-agent-mcp-server",
      "cwe": "CWE-73",
      "title": "Argument injection in the diff scan operation in AWS security-agent-mcp-server allows arbitrary host file creation, overwrite, and truncation outside the intended workspace",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97662"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-100251",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wormhole App",
      "product": "Wormhole",
      "cwe": "CWE-918",
      "title": "Wormhole.app SSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100251"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-102666",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joyland",
      "product": "Joyland.ai",
      "cwe": "CWE-798",
      "title": "Joyland AI hard-coded credentials for push notifications",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102666"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-102668",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joyland",
      "product": "Joyland.ai",
      "cwe": "CWE-295",
      "title": "Joyland AI accepts TLS certificates without validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102668"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-102669",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joyland",
      "product": "Joyland.ai",
      "cwe": "CWE-297",
      "title": "Joyland AI hostname checking disabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102669"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-102671",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joyland",
      "product": "Joyland.ai",
      "cwe": "CWE-295",
      "title": "Joyland AI WebView accepts invalid SSL certificates",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102671"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-103245",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-347",
      "title": "n8n before 1.123.80, 2.39.6, and 2.40.1 Missing Webhook Signature Verification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103245"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-103249",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-79",
      "title": "n8n before 1.123.80, 2.39.6, and 2.40.1 Stored DOM XSS via Resource Locator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103249"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-103258",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-943",
      "title": "n8n before 2.39.6 and 2.40.x before 2.40.1 Filter Bypass via Parameter Interpolation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103258"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-103261",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tornadoweb",
      "product": "tornado",
      "cwe": "CWE-770",
      "title": "Tornado before 6.5.9 Denial of Service via Query String",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103261"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-103269",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-862",
      "title": "Ghost 5.3.0 before 6.62.0 Missing Authorization via Post Excerpts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103269"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-103274",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-862",
      "title": "Ghost 5.3.0 before 6.58.0 Unauthenticated Comment Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103274"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-103276",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-173",
      "title": "Ghost before 6.20.0 File Read via URL Encoding Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103276"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-103280",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-201",
      "title": "Ghost 0.8.0 before 6.23.0 Information Disclosure via Setup Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103280"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-103505",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "aws-efs-csi-driver",
      "cwe": "CWE-88",
      "title": "AWS EFS CSI Driver Mount Option Injection via mounttargetipmap",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103505"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-103532",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "immich-app",
      "product": "Immich",
      "cwe": "CWE-266",
      "title": "immich-app Immich Shared Link Preview access.ts checkSharedLinkAccess improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103532"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-78249",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fujifilm Business Innovation Corp.",
      "product": "Apeos 3060 / 2560 / 1860 Japan model",
      "cwe": "CWE-22",
      "title": "A path traversal vulnerability exists in the web management interface of multiple Multifunction Devices and Printers, including Apeos C4571 1.1.3 and earlier, Apeos C3567 1.1.3, or other products listed, specifically in the handling of externally supplied parameters. If the device receives a specially crafted, malicious request, it may trigger unintended processing.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78249"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-12545",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Satellite 6.16 for RHEL 8",
      "cwe": "CWE-78",
      "title": "Rubygem-hammer_cli: command injection via insecure editor invocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12545"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-103494",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-266",
      "title": "In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group membership changes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103494"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-55251",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netbox-community",
      "product": "devicetype-library",
      "cwe": "CWE-94",
      "title": "NetBox Device Type Library: Arbitrary Code Execution on CI Runner Through Malicious requirements.txt, .pre-commit-hooks-config.yaml, and .gitmodules Files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55251"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-56097",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Satellite 6.16 for RHEL 8",
      "cwe": "CWE-89",
      "title": "Rubygem-katello: sql injection in registry proxy via labels",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56097"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-67075",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "Digital Experience",
      "cwe": "CWE-79",
      "title": "HCL Digital Experience is affected by improper input sanitation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67075"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-79900",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fortra",
      "product": "BoKS Manager boks-server",
      "cwe": "CWE-787",
      "title": "Heap overflow in KSL checksum initialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79900"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-90974",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Fusion Lite",
      "cwe": "CWE-862",
      "title": "WP Fusion Lite 3.37.14 - 3.47.14 - Unauthenticated CRM Integration Settings Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90974"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-91109",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "croixhaug",
      "product": "Simply Schedule Appointments",
      "cwe": "CWE-639",
      "title": "Simply Schedule Appointments <= 1.6.12.31 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Disclosure via 'complete_group' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91109"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-97251",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "magepeopleteam",
      "product": "Bus Ticket Booking with Seat Reservation",
      "cwe": "CWE-639",
      "title": "WordPress Bus Ticket Booking with Seat Reservation plugin <= 5.9.3 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97251"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-97258",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Aruba.it",
      "product": "Aruba Migration Tool",
      "cwe": "CWE-862",
      "title": "WordPress Aruba Migration Tool plugin <= 1.0.4 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97258"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-97269",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPFunnels",
      "product": "WPFunnels",
      "cwe": "CWE-639",
      "title": "WordPress WPFunnels plugin <= 3.13.1 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97269"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-97280",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mamunur Rashid",
      "product": "Review Schema",
      "cwe": "CWE-862",
      "title": "WordPress Review Schema plugin 3.1.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97280"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-102394",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPDeveloper",
      "product": "Essential Addons for Elementor",
      "cwe": "CWE-79",
      "title": "WordPress Essential Addons for Elementor plugin <= 6.8.4 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102394"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-103063",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wpmet",
      "product": "ElementsKit Elementor addons Lite",
      "cwe": "CWE-79",
      "title": "WordPress ElementsKit Elementor addons Lite plugin <= 4.0.6 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103063"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-103064",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wpmet",
      "product": "ElementsKit Elementor addons Lite",
      "cwe": "CWE-79",
      "title": "WordPress ElementsKit Elementor addons Lite plugin <= 4.0.6 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103064"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-103339",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wpmet",
      "product": "Metform",
      "cwe": "CWE-79",
      "title": "WordPress Metform plugin <= 4.3.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103339"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-103343",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP ManageNinja LLC",
      "product": "FluentForm",
      "cwe": "CWE-79",
      "title": "WordPress FluentForm plugin <= 6.2.14 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103343"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-103491",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-639",
      "title": "In JetBrains YouTrack before 2026.2.19422 iDOR in the issue activities API allowed reading restricted issues",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103491"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-103492",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-835",
      "title": "In JetBrains YouTrack before 2026.2.19422 doS attack was possible via crafted PSD attachments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103492"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-103679",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "tnef",
      "cwe": "CWE-416",
      "title": "Tnef: use-after-free and double-free in get_body_files() via multi-value body extraction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103679"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-103884",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-22",
      "title": "Keycloak-services: keycloak-services: path traversal in x.509 crl distribution point allows arbitrary local file read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103884"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-86610",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Download Manager",
      "cwe": "CWE-79",
      "title": "Download Manager < 3.3.71 - Author+ Stored XSS via Package Icon",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86610"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-89424",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "inisev",
      "product": "Duplicate Post",
      "cwe": "CWE-79",
      "title": "Duplicate Post <= 1.5.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'noti_token' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89424"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-90992",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "davidanderson",
      "product": "Redux Framework",
      "cwe": "CWE-79",
      "title": "Redux Framework <= 4.5.14 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'user-mediaurl' Media Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90992"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-94212",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache APISIX",
      "cwe": "CWE-347",
      "title": "Apache APISIX: unauthenticated impersonation issue in saml-auth",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94212"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-96256",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpdevteam",
      "product": "Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns",
      "cwe": "CWE-79",
      "title": "Gutenberg Essential Blocks <= 6.4.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'marker' Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96256"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-96268",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "awesomesupport",
      "product": "Awesome Support – WordPress HelpDesk & Support Plugin",
      "cwe": "CWE-79",
      "title": "Awesome Support <= 6.4.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'gdpr-data' Parameter via wpas_gdpr_user_opt_out AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96268"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-101925",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "robin-w",
      "product": "bbp style pack",
      "cwe": "CWE-79",
      "title": "bbp style pack <= 6.4.8 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Author Display Name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101925"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-64892",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Johnson Controls",
      "product": "Easy IO Neo",
      "cwe": "CWE-200",
      "title": "- Exposure of Sensitive Information vulnerability in Johnson Controls Easy IO Neo allows Collect Data from Common Resource Locations. This issue affects Easy IO Neo: before 3.3b63.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64892"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-94269",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache APISIX",
      "cwe": "CWE-647",
      "title": "Apache APISIX: Servlet-style normalization creates a route/upstream authorization mismatch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94269"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-97281",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "weDevs",
      "product": "WP Project Manager",
      "cwe": "CWE-862",
      "title": "WordPress WP Project Manager plugin <= 4.0.7 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97281"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-102505",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "Imager",
      "cwe": "CWE-131",
      "title": "Imager versions before 1.037 for Perl overflow a heap buffer fetching float samples from a paletted image in i_gsampf_fp",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102505"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-103004",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vercel",
      "product": "next.js",
      "cwe": "CWE-524",
      "title": "next.js cache leak on warm `use cache` handlers accessing root param",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103004"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-103260",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-862",
      "title": "n8n before 2.39.6 and 2.40.x before 2.40.1 Approval Bypass via Send and Wait Node",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103260"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-104058",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "akhilrex",
      "product": "podgrab",
      "cwe": "CWE-306",
      "title": "Podgrab Missing Authentication on WebSocket /ws Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104058"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-104182",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "uhop",
      "product": "stream-json",
      "cwe": "CWE-407",
      "title": "stream-json: JSONC parser and verifier re-scan the whole accumulated comment on every input chunk",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104182"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-19902",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "spacetime",
      "product": "Ad Inserter – Ad Manager & AdSense Ads",
      "cwe": "CWE-79",
      "title": "Ad Inserter <= 2.8.18 - Reflected Cross-Site Scripting via {search-query} Dynamic Tag (Referer Header)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19902"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-83589",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift Container Platform 4",
      "cwe": "CWE-601",
      "title": "Oauth-proxy: open redirect via /\\ and /\\t bypass in post-login redirect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83589"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-89047",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "inisev",
      "product": "Social Media Share Buttons & Social Sharing Icons",
      "cwe": "CWE-79",
      "title": "Social Media Share Buttons & Social Sharing Icons <= 3.0.1 - Reflected DOM-Based Cross-Site Scripting via URL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89047"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-89427",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "spacetime",
      "product": "Ad Inserter – Ad Manager & AdSense Ads",
      "cwe": "CWE-79",
      "title": "Ad Inserter <= 2.8.18 - Reflected Cross-Site Scripting via 's' Search Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89427"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-100179",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "codepeople",
      "product": "Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More",
      "cwe": "CWE-79",
      "title": "Calculated Fields Form <= 5.5.1.3 - Reflected DOM-Based Cross-Site Scripting via 'x' URL Parameter via setChoices()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100179"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-104002",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "powertools-lambda-python",
      "cwe": "CWE-390",
      "title": "Fail-open error handling in the data masking utility in Powertools for AWS Lambda (Python)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104002"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-34189",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pandora FMS",
      "product": "Pandora FMS",
      "cwe": "CWE-352",
      "title": "CSRF in Event Response Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34189"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-34190",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pandora FMS",
      "product": "Pandora FMS",
      "cwe": "CWE-352",
      "title": "CSRF in Alert Command Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34190"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-76147",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Genians, Inc",
      "product": "Genian NAC 4.0.175 Release",
      "cwe": "CWE-22",
      "title": "Genians, Inc Genian NAC/ZTNA Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76147"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-103754",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2",
      "cwe": "CWE-22",
      "title": "Ansible-runner: ansible-runner: path traversal and symlink escape in unstream_dir() allows file write outside the target directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103754"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-71454",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CWE-79 - Cross-site Scripting",
      "product": "CAPEC-63",
      "cwe": "CWE-79",
      "title": "Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in CWE-79 - Cross-site Scripting CAPEC-63 allows Cross-Site Scripting (XSS). This issue affects CAPEC-63: before 3.0b63.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71454"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-103247",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-639",
      "title": "n8n before 1.123.80 Credential Tampering via Duplicate Node IDs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103247"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-78242",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache APISIX",
      "cwe": "CWE-532",
      "title": "Apache APISIX: data-mask may fail to redact request headers in logger output",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78242"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-27872",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Johnson Controls",
      "product": "Easy IO FG",
      "cwe": "CWE-269",
      "title": "EasyIO FG",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27872"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-27873",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Johnson Controls",
      "product": "EasyIO FG",
      "cwe": "CWE-798",
      "title": "- Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FG allows - Pasword Spraying. This issue affects EasyIO FG: before 2.0b52.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27873"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-71448",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Johnson Controls",
      "product": "EasyIO FS32",
      "cwe": "CWE-1188",
      "title": ": Insecure Default Initialization of Resource vulnerability in Johnson Controls EasyIO FS32 allows : Authentication Abuse. This issue affects EasyIO FS32: before 3.0b63.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71448"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-71451",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Johnson Controls",
      "product": "EasyIO FS32",
      "cwe": "CWE-78",
      "title": "- OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows - Command Injection. This issue affects EasyIO FS32: before 3.0b63.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71451"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-71453",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Johnson Controls",
      "product": "EasyIO FS32",
      "cwe": "CWE-73",
      "title": "- External Control of File Name or Path vulnerability in Johnson Controls EasyIO FS32 allows - traversal attack. This issue affects EasyIO FS32: before 3.0b63.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71453"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-103497",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-918",
      "title": "In JetBrains YouTrack before 2026.2.19422 sSRF was possible via the GitHub VCS integration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103497"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-103536",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZongXR",
      "product": "Supermarket",
      "cwe": "CWE-287",
      "title": "ZongXR Supermarket save Endpoint OrderController.java OrderController.addOrder missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103536"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-103538",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZongXR",
      "product": "SuperMarket",
      "cwe": "CWE-287",
      "title": "ZongXR SuperMarket Order Deletion Endpoint OrderController.java OrderController.deleteOrder missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103538"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-103641",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-125",
      "title": "Gegl: gegl04: gegl: out-of-bounds read in the radiance hdr uncompressed scanline decoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103641"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-103687",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rhukster",
      "product": "dom-sanitizer",
      "cwe": "CWE-183",
      "title": "rhukster dom-sanitizer SVG Sanitization DOMSanitizer.php url incomplete blacklist",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103687"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-12241",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mihail-barinov",
      "product": "Advanced Woo Labels – Product Labels & Badges for WooCommerce",
      "cwe": "CWE-79",
      "title": "Advanced Woo Labels – Product Labels & Badges for WooCommerce <= 2.51 - Improper Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12241"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-62063",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Magepeople inc.",
      "product": "WpTravelly",
      "cwe": "CWE-862",
      "title": "WordPress WpTravelly plugin <= 2.3.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62063"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-90972",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Fusion Lite",
      "cwe": "CWE-284",
      "title": "WP Fusion Lite < 3.48.0 - Subscriber+ User Email Disclosure and Cross-User CRM Data Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90972"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-102370",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Kasa EC70 V4",
      "cwe": "CWE-1191",
      "title": "Physical UART Access Leading to an Unauthenticated Root Shell in TP-Link Kasa EC70 and EC71",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102370"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-103496",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-639",
      "title": "In JetBrains YouTrack before 2026.2.19422 iDOR in inbox threads allowed reading other users' notifications",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103496"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-103678",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "tnef",
      "cwe": "CWE-125",
      "title": "Tnef: heap out-of-bounds read in get_rtf_data_from_buf() via uncompressed rtf mapi value",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103678"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-104181",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "filamentphp",
      "product": "filament",
      "cwe": "CWE-306",
      "title": "Filament: Multi-factor authentication (app) management actions do not require password reauthentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104181"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-12542",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Satellite 6.16 for RHEL 8",
      "cwe": "CWE-78",
      "title": "Foreman: command injection in foreman-tail",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12542"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-55394",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Teledyne FLIR",
      "product": "Aware2",
      "cwe": "CWE-319",
      "title": "Unencrypted 802.11 Network in Teledyne FLIR Robots running Aware2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55394"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-58415",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache HTTP Server",
      "cwe": "CWE-552",
      "title": "Apache HTTP Server: mod_dav_fs property database read access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58415"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-62058",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPExperts",
      "product": "CF7 Apps",
      "cwe": "CWE-201",
      "title": "WordPress CF7 Apps plugin <= 3.7.2 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62058"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-62061",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Metagauss",
      "product": "ProfileGrid",
      "cwe": "CWE-639",
      "title": "WordPress ProfileGrid plugin <= 6.0.0.2 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62061"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-67104",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "HCL BigFix Service Management",
      "cwe": "CWE-200",
      "title": "HCL BigFix Service Management is affected by multiple security vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67104"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-67106",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "HCL BigFix Service Management",
      "cwe": "CWE-200",
      "title": "HCL BigFix Service Management is affected by multiple security vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67106"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-67171",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "HCL BigFix Service Management",
      "cwe": "CWE-200",
      "title": "HCL BigFix Service Management is affected by multiple security vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67171"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-78577",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Tapo C200 v5",
      "cwe": "CWE-306",
      "title": "Unauthenticated Onboarding Scan Information Disclosure in TP-Link Tapo C120 & C200",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78577"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-79768",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache HTTP Server",
      "cwe": "CWE-55",
      "title": "Apache HTTP Server: mod_userdir information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79768"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-82806",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache APISIX",
      "cwe": "CWE-488",
      "title": "Apache APISIX: cross-request permission pollution via static permission list mutation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82806"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-92537",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "satollo",
      "product": "Newsletter – Send awesome emails from WordPress",
      "cwe": "CWE-522",
      "title": "Newsletter <= 9.3.9 - Unauthenticated Insufficiently Protected Credentials via '/tnp/l/' Click-Tracking REST Endpoint (Raw Subscriber Token Cookie Disclosure)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92537"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-92548",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hcabrera",
      "product": "WP Popular Posts",
      "cwe": "CWE-200",
      "title": "WP Popular Posts <= 7.4.2 - Unauthenticated Information Disclosure in 'post_type' and 'context' Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92548"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-96173",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Payments for Hubtel",
      "cwe": "CWE-639",
      "title": "Payments for Hubtel < 1.0.2 - Unauthenticated Order Key Disclosure via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96173"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-96200",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Payments for Hubtel",
      "cwe": "CWE-862",
      "title": "Payments for Hubtel < 1.0.2 - Unauthenticated Payment Confirmation Forgery via Delayed Payment Callback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96200"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-102381",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ahmad",
      "product": "Majestic Support",
      "cwe": "CWE-862",
      "title": "WordPress Majestic Support plugin <= 1.2.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102381"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-102390",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VillaTheme",
      "product": "AFFI – Affiliate Marketing for WooCommerce",
      "cwe": "CWE-862",
      "title": "WordPress AFFI – Affiliate Marketing for WooCommerce plugin <= 1.0.9 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102390"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-102670",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joyland",
      "product": "Joyland.ai",
      "cwe": "CWE-319",
      "title": "Joyland AI enables HTTP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102670"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-103265",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fleetdm",
      "product": "fleet",
      "cwe": "CWE-863",
      "title": "Fleet before 4.89.0 Information Disclosure via MDM Command Results",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103265"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-103267",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-807",
      "title": "Ghost 0.5.0 before 6.62.0 Arbitrary Email Registration via Staff Invite",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103267"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-103273",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-863",
      "title": "Ghost 4.3.0 before 6.58.0 Incorrect Authorization via Staff Token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103273"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-103275",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-203",
      "title": "Ghost 5.42.2 before 6.58.0 Password Hash Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103275"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-103281",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-201",
      "title": "Ghost 3.23.0 before 6.23.0 API Key Exposure via Admin API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103281"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-103282",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-362",
      "title": "Ghost 0.5.0 before 6.23.0 Multiple Account Creation via Invite Token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103282"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-103284",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-863",
      "title": "Ghost 5.125.1 before 6.57.1 Information Disclosure via Feedback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103284"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-103285",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-352",
      "title": "Ghost 5.19.0 before 6.57.1 Cross-Site Request Forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103285"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-103291",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-918",
      "title": "Ghost 3.20.2 before 6.51.0 SSRF via image-size fetch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103291"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-103336",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Smackcoders Inc.",
      "product": "WP Ultimate CSV Importer",
      "cwe": "CWE-201",
      "title": "WordPress WP Ultimate CSV Importer plugin <= 9.1 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103336"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-103340",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gemini Labs",
      "product": "Site Reviews",
      "cwe": "CWE-862",
      "title": "WordPress Site Reviews plugin <= 8.3.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103340"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-103341",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unlimited Elements",
      "product": "Unlimited Elements For Elementor (Free Widgets, Addons, Templates)",
      "cwe": "CWE-862",
      "title": "WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.20 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103341"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-103345",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shamim Rajani",
      "product": "Pie Register",
      "cwe": "CWE-201",
      "title": "WordPress Pie Register plugin <= 3.8.4.13 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103345"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-103347",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hcaptcha",
      "product": "hCaptcha for WP",
      "cwe": "CWE-290",
      "title": "WordPress hCaptcha for WP plugin <= 5.3.0 - Bypass Vulnerability vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103347"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-103353",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP ManageNinja LLC",
      "product": "FluentForm",
      "cwe": "CWE-696",
      "title": "WordPress FluentForm plugin <= 6.2.14 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103353"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-103858",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-285",
      "title": "MISP Incomplete Thread Authorization Allows Unauthorized Read and Post Access to Discussions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103858"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-55252",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openrundev",
      "product": "openrun",
      "cwe": "CWE-601",
      "title": "OpenRun: Redirect URL validation bypass using //host paths leads to Open Redirect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55252"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-94276",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache APISIX",
      "cwe": "CWE-287",
      "title": "Apache APISIX: Openid-connect introspection validation issue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94276"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-101890",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Codexonics",
      "product": "Prime Mover",
      "cwe": "CWE-79",
      "title": "Prime Mover < 2.2.1 Stored XSS via Package Metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101890"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-103287",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-918",
      "title": "Ghost 1.18.0 before 6.27.0 Server-Side Request Forgery via Webhook",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103287"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-103290",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-35",
      "title": "Ghost 6.14.0 before 6.27.0 Path Traversal via ImageSize",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103290"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-103531",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "OpenSC",
      "cwe": "CWE-119",
      "title": "OpenSC card-setcos.c setcos_construct_fci_44 stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103531"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-103662",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-79",
      "title": "MISP Reflected XSS in Taxonomy Tag Confirmation Forms",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103662"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-104183",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "uhop",
      "product": "stream-json",
      "cwe": "CWE-1321",
      "title": "stream-json: Prototype pollution: Assembler writes this.current[this.key] on plain objects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104183"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-27874",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Johnson Controls",
      "product": "EasyIO FS32",
      "cwe": "CWE-798",
      "title": ": Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FS32 allows : Exploitation of Default or Hard-coded Credentials. This issue affects EasyIO FS32: before 3.0b63.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27874"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-7173",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Crocantickets",
      "product": "Entradium",
      "cwe": "CWE-79",
      "title": "Multiple vulnerabilities in Entradium by Crocantickets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7173"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-7174",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Crocantickets",
      "product": "Entradium",
      "cwe": "CWE-79",
      "title": "Multiple vulnerabilities in Entradium by Crocantickets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7174"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-7175",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Crocantickets",
      "product": "Entradium",
      "cwe": "CWE-79",
      "title": "Multiple vulnerabilities in Entradium by Crocantickets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7175"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-7176",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Crocantickets",
      "product": "Entradium",
      "cwe": "CWE-79",
      "title": "Multiple vulnerabilities in Entradium by Crocantickets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7176"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-9864",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fortra",
      "product": "Core Privileged Access Manager (BoKS)",
      "cwe": "CWE-338",
      "title": "Fortra BoKS Server Agent adjoin machine-account password generation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9864"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-93832",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Motorola",
      "product": "Setup App",
      "cwe": "CWE-862",
      "title": "A component of one of the Motorola system applications was exported without permission, allowing for the revocation of runtime permissions from other apps.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93832"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-103664",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-79",
      "title": "MISP Reflected Cross-Site Scripting via Unsanitized Analyst Data Seed Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103664"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-87970",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "If-So Dynamic Content",
      "cwe": "CWE-79",
      "title": "If-So Dynamic Content 1.8 - 1.10.1 - Reflected XSS via render_ifso_shortcodes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87970"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-100184",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "codepeople",
      "product": "Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More",
      "cwe": "CWE-79",
      "title": "Calculated Fields Form <= 5.5.1.3 - Reflected DOM-Based Cross-Site Scripting via 'x' URL Query Parameter via Text Area Predefined Value",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100184"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-17053",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-862",
      "title": "SMBus callback-removal syscalls accept an unvalidated user pointer, letting user threads manipulate kernel callback state",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17053"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2025-31980",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "HCL BigFix Service Management",
      "cwe": "CWE-20",
      "title": "HCL BigFix Service Management is affected by multiple security vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-31980"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-42528",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache HTTP Server",
      "cwe": "CWE-789",
      "title": "Apache HTTP Server: mod_dav shared lock overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42528"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-56098",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Satellite 6.16 for RHEL 8",
      "cwe": "CWE-203",
      "title": "Rubygem-katello: improper authorization logic allows resource enumeration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56098"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2026-66247",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "iControl",
      "cwe": "CWE-942",
      "title": "iControl is affected by an insecure Cross-Origin Resource Sharing (CORS) policy vulnerability, which could allow a malicious website to execute cross-origin requests with included credentials, enabling an attacker to access and exfiltrate sensitive data within the context of the victim's active session.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66247"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-88999",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "davidanderson",
      "product": "Redux Framework",
      "cwe": "CWE-862",
      "title": "Redux Framework <= 4.5.14 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Attachment Deletion via 'attachment_id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88999"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-102382",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ahmad",
      "product": "Majestic Support",
      "cwe": "CWE-639",
      "title": "WordPress Majestic Support plugin <= 1.2.0 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102382"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-103495",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-862",
      "title": "In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed reloading of translation catalogs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103495"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-77387",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "geopy",
      "product": "geopy",
      "cwe": "CWE-1333",
      "title": "geopy: Regular Expression Denial of Service (ReDoS) in geopy.Point",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77387"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-21833",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "AION",
      "cwe": "CWE-1032",
      "title": "HCL AION is susceptible to a Missing \"Content-Security-Policy\" header Vulnerability (CVE-2026-21833)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21833"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2026-42356",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache HTTP Server",
      "cwe": "CWE-430",
      "title": "Apache HTTP Server: limited RCE for some internal redirects to non-CGI files in CGI directories",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42356"
    },
    {
      "rank": 354,
      "cve_id": "CVE-2026-67172",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "HCL BigFix Service Management",
      "cwe": "CWE-200",
      "title": "HCL BigFix Service Management is affected by multiple security vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67172"
    },
    {
      "rank": 355,
      "cve_id": "CVE-2026-66248",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "iControl",
      "cwe": "CWE-209",
      "title": "HCL iControl is affected by an Improper Error Handling vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66248"
    },
    {
      "rank": 356,
      "cve_id": "CVE-2026-66249",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "iControl",
      "cwe": "CWE-614",
      "title": "HCL iControl is affected by a Missing Secure Attribute vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66249"
    },
    {
      "rank": 357,
      "cve_id": "CVE-2026-66253",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "iControl",
      "cwe": "CWE-613",
      "title": "HCL iControl is affected by a Session Timeout vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66253"
    },
    {
      "rank": 358,
      "cve_id": "CVE-2026-87973",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "If-So Dynamic Content",
      "cwe": "CWE-79",
      "title": "If-So Dynamic Content 1.9.9 - 1.10.1 - Editor+ Stored XSS via Conversion Name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87973"
    },
    {
      "rank": 359,
      "cve_id": "CVE-2026-103680",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "tnef",
      "cwe": "CWE-787",
      "title": "Tnef: heap buffer overflow in find_free_number() via numbered-backup suffix generation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103680"
    },
    {
      "rank": 360,
      "cve_id": "CVE-2026-56599",
      "cvss_base": 2.2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "HCL BigFix Service Management",
      "cwe": "CWE-614",
      "title": "HCL BigFix Service Management is affected by multiple security vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56599"
    },
    {
      "rank": 361,
      "cve_id": "CVE-2026-94220",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache APISIX",
      "cwe": "CWE-352",
      "title": "Apache APISIX: session fixation issue in feishu-auth and dingtalk-auth plugin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94220"
    },
    {
      "rank": 362,
      "cve_id": "CVE-2026-101887",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "arkq",
      "product": "bluez-alsa",
      "cwe": "CWE-369",
      "title": "BlueALSA bluealsad LC3plus Decoder Division-by-Zero DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101887"
    },
    {
      "rank": 363,
      "cve_id": "CVE-2026-103534",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "David-Crty",
      "product": "databasement",
      "cwe": "CWE-266",
      "title": "David-Crty databasement Snapshot Model snapshots SnapshotPolicy.view access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103534"
    },
    {
      "rank": 364,
      "cve_id": "CVE-2026-103539",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZongXR",
      "product": "SuperMarket",
      "cwe": "CWE-287",
      "title": "ZongXR SuperMarket Instant Buy InstantBuyController.java startBuy missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103539"
    },
    {
      "rank": 365,
      "cve_id": "CVE-2026-103540",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "formtools.org",
      "product": "Form Tools",
      "cwe": "CWE-791",
      "title": "formtools.org Form Tools Client Settings Clients.class.php updateClientSettingsTab special elements in template engine",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103540"
    },
    {
      "rank": 366,
      "cve_id": "CVE-2026-103541",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "formtools.org",
      "product": "Form Tools",
      "cwe": "CWE-284",
      "title": "formtools.org Form Tools Ajax actions.php uploadFile unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103541"
    },
    {
      "rank": 367,
      "cve_id": "CVE-2026-103542",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "formtools.org",
      "product": "Form Tools",
      "cwe": "CWE-918",
      "title": "formtools.org Form Tools AJAX Endpoint actions.php smart_fill server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103542"
    },
    {
      "rank": 368,
      "cve_id": "CVE-2026-103543",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Leave Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Leave Management System controller.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103543"
    },
    {
      "rank": 369,
      "cve_id": "CVE-2026-103544",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "datadrivenconstruction",
      "product": "OpenConstructionERP",
      "cwe": "CWE-488",
      "title": "datadrivenconstruction OpenConstructionERP Al Provider Configuration ai_client.py wrong session",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103544"
    },
    {
      "rank": 370,
      "cve_id": "CVE-2026-103690",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Leave Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Leave Management System controller.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103690"
    },
    {
      "rank": 371,
      "cve_id": "CVE-2026-103923",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "KaTeX",
      "product": "KaTeX",
      "cwe": "CWE-807",
      "title": "KaTeX: Existing prototype pollution can bypass trust restrictions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103923"
    },
    {
      "rank": 372,
      "cve_id": "CVE-2026-103489",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-79",
      "title": "In JetBrains YouTrack before 2026.2.19422 hTML injection in VCS command failure notifications was possible",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103489"
    },
    {
      "rank": 373,
      "cve_id": "CVE-2026-103686",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rhukster",
      "product": "dom-sanitizer",
      "cwe": "CWE-79",
      "title": "rhukster dom-sanitizer URL Validation DOMSanitizer.php isDangerousUrl cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103686"
    },
    {
      "rank": 374,
      "cve_id": "CVE-2026-76144",
      "cvss_base": 1.8,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Genians, Inc",
      "product": "Genian SSL PNS (frodo-core)",
      "cwe": "CWE-434",
      "title": "Genians, Inc Genian SSL PNS Unrestricted File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76144"
    },
    {
      "rank": 375,
      "cve_id": "CVE-2026-103533",
      "cvss_base": 1.2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "David-Crty",
      "product": "databasement",
      "cwe": "CWE-22",
      "title": "David-Crty databasement database-servers API Endpoint RestoreRequest.php 511 path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103533"
    },
    {
      "rank": 376,
      "cve_id": "CVE-2026-51873",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Devika v1.0 is vulnerable to Directory Traversal in the Coder.save_code_to_project function, which allows attackers to write files outside the intended project workspace.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51873"
    },
    {
      "rank": 377,
      "cve_id": "CVE-2026-51874",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "In Devika v1.0, the Patcher Agent save_code_to_project function contains a path traversal vulnerability that allows attackers to write files outside the intended project workspace.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51874"
    },
    {
      "rank": 378,
      "cve_id": "CVE-2026-51875",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "In Devika v1.0, the Feature Agent save_code_to_project function contains a path traversal vulnerability that allows attackers to write files outside the intended project workspace, potentially compromising the entire server.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51875"
    },
    {
      "rank": 379,
      "cve_id": "CVE-2026-51876",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "DeepTutor 1.4.0 contains an authorization bypass vulnerability in the book confirmation flow. An unauthenticated or unauthorized caller can reuse a publicly exposed book_id to submit a confirm-proposal request for an existing book, causing unauthorized overwrites of persisted metadata and spine content.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51876"
    },
    {
      "rank": 380,
      "cve_id": "CVE-2026-51878",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "deeptutor 1.4.0 contains an authorization bypass through a user-controlled object identifier in TurnRuntimeManager.regenerate_last_turn. A remote caller can enumerate or obtain a session_id and trigger regenerate on another user's session.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51878"
    },
    {
      "rank": 381,
      "cve_id": "CVE-2026-51879",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "deeptutor 1.4.0 contains an authorization bypass through a user-controlled object identifier in TutorBotManager.write_bot_file. A remote caller can enumerate bot IDs and overwrite another bot's whitelisted control files through the HTTP tutorbot file route.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51879"
    },
    {
      "rank": 382,
      "cve_id": "CVE-2026-51880",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "deeptutor 1.4.0 contains a path traversal issue in EditFileTool.execute. Through the live tutorbot WebSocket interface, a remote caller can induce the tool layer to write or edit absolute paths outside the intended bot workspace.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51880"
    },
    {
      "rank": 383,
      "cve_id": "CVE-2026-51881",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "deeptutor 1.4.0 contains code injection in ExecTool.execute. Through the live tutorbot WebSocket interface, a remote caller can induce the tool layer to execute reviewer-chosen shell commands in the service environment.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51881"
    },
    {
      "rank": 384,
      "cve_id": "CVE-2026-51882",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "The OpenAI-compatible file upload endpoint `/v1/files` in Langchain-Chatchat 0.3.0 is vulnerable to path traversal. An attacker can write files to arbitrary locations outside the `openai_files` directory by crafting malicious filenames.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51882"
    },
    {
      "rank": 385,
      "cve_id": "CVE-2026-51883",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "The knowledge base creation and document upload interfaces in Langchain-Chatchat 0.3.0;0.3.1 is vulnerable to path traversal. An attacker can inject path traversal sequences (such as `..\\`) into the `knowledge_base_name` parameter to write knowledge base content to arbitrary locations outside the configured knowledge base root directory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51883"
    },
    {
      "rank": 386,
      "cve_id": "CVE-2026-51884",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "The /knowledge_base/upload_temp_docs temporary document upload endpoint in Langchain Chatchat 0.3.1 is vulnerable to path traversal. By crafting malicious filenames, an attacker can write files to arbitrary locations on the server, bypassing the intended restrictions on the temporary directory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51884"
    },
    {
      "rank": 387,
      "cve_id": "CVE-2026-51886",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "langflow-ai langflow v1.9.3 is affected by: Code Injection. The impact is: execute arbitrary code (remote). The component is: src/backend/base/langflow/api/v1/validate.py:validate-post_validate_code-a-real-authenticated-http-post-to-api-v1. The attack vector is: Attack surface: HTTP or browser-backed service path. A public-facing route accepts raw Python source and forwards it into a server-side compile/exec validation path without any visible entitlement guard. ¶¶ A weakness has been identified in langflow-ai langflow up to 1.9.3. langflow contains a code injection vulnerability in validate-post_validate_code-a-real-authenticated-http-post-to-api-v1 (src/backend/base/langflow/api/v1/validate.py:13). An authenticated attacker can execute arbitrary Python code on the server by submitting malicious code to the /api/v1/validate/code endpoint, which directly executes user-supplied code without sandboxing or security controls.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51886"
    },
    {
      "rank": 388,
      "cve_id": "CVE-2026-51888",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "langflow-ai langflow v1.8.4 is affected by: Directory Traversal. The impact is: Arbitrary file write outside the intended workspace or storage boundary.. The component is: src/backend/base/langflow/api/v1/knowledge_bases.py:knowledge_bases-create_knowledge_base-a-live-http-post-to-create-knowledge-base. The attack vector is: Attack surface: HTTP or browser-backed service path. A public-facing upload or HTTP route handler forwards an attacker-controlled path or filename into host file creation without any visible boundary enforcement. ¶¶ A weakness has been identified in langflow-ai langflow up to 1.8.4. langflow contains an absolute path traversal vulnerability in knowledge_bases-create_knowledge_base-a-live-http-post-to-create-knowledge-base (src/backend/base/langflow/api/v1/knowledge_bases.py:51). An attacker can write or overwrite files outside the intended working directory by providing absolute paths in the knowledge base creation endpoint.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51888"
    },
    {
      "rank": 389,
      "cve_id": "CVE-2026-51892",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via /v1/document/get/<doc_id>.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51892"
    },
    {
      "rank": 390,
      "cve_id": "CVE-2026-51893",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via trace_mindmap. An externally reachable path accepts a caller-selected object or tenant identifier and reaches a data-access operation without a visible owner, tenant, workspace, or membership binding on that object.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51893"
    },
    {
      "rank": 391,
      "cve_id": "CVE-2026-51894",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via run_mindmap. A reachable path accepts a caller-selected object or tenant identifier and reaches a data-access operation without a visible owner, tenant, workspace, or membership binding on that object.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51894"
    },
    {
      "rank": 392,
      "cve_id": "CVE-2026-51895",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Ragflow 0.24.0 and prior contains improper access control in update_metadata_setting (api/apps/kb_app.py). Depending on the exposed entry, an attacker can perform unauthorized cross-session or privilege-crossing operations.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51895"
    },
    {
      "rank": 393,
      "cve_id": "CVE-2026-51896",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "infiniflow ragflow 0.25.3 contains improper access control in resume (api/apps/connector_app.py). Depending on the exposed entry, an attacker can perform unauthorized cross-session or privilege-crossing operations.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51896"
    },
    {
      "rank": 394,
      "cve_id": "CVE-2026-51897",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "RAGFlow 0.24.0 contains improper access control in get_dataset (api/apps/evaluation_app). Depending on the exposed entry, an attacker can trigger attacker-controlled code or command execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51897"
    },
    {
      "rank": 395,
      "cve_id": "CVE-2026-104056",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Authlib",
      "product": "Authlib",
      "cwe": null,
      "title": "CVE-2026-104056",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104056"
    }
  ],
  "transactions": [
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-104286",
      "detail": "ADDED TO KEV — CVE-2026-104286 (Fortinet FortiMail). Remediation due October 4, 2026."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2010-0738",
      "detail": "EXPLOIT PUBLISHED — CVE-2010-0738. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2010-1428",
      "detail": "EXPLOIT PUBLISHED — CVE-2010-1428. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2010-2861",
      "detail": "EXPLOIT PUBLISHED — CVE-2010-2861. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2015-2291",
      "detail": "EXPLOIT PUBLISHED — CVE-2015-2291. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2016-20076",
      "detail": "EXPLOIT PUBLISHED — CVE-2016-20076 (ChrisHurst Simple Backup). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2018-19323",
      "detail": "EXPLOIT PUBLISHED — CVE-2018-19323. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2018-6882",
      "detail": "EXPLOIT PUBLISHED — CVE-2018-6882. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2019-25743",
      "detail": "EXPLOIT PUBLISHED — CVE-2019-25743 (Soliloquywp Soliloquy Lite). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2020-0796",
      "detail": "EXPLOIT PUBLISHED — CVE-2020-0796 (Microsoft Windows 10 Version 1903 for 32-bit Systems). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-21975",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-21975 (VMware vRealize Operations). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-22175",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-22175 (GitLab). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-27065",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-27065 (Microsoft Exchange Server 2013 Cumulative Update 21). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2022-27925",
      "detail": "EXPLOIT PUBLISHED — CVE-2022-27925. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2022-30333",
      "detail": "EXPLOIT PUBLISHED — CVE-2022-30333. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2023-46805",
      "detail": "EXPLOIT PUBLISHED — CVE-2023-46805 (Ivanti ICS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2023-54342",
      "detail": "EXPLOIT PUBLISHED — CVE-2023-54342 (Eclipse Equinox OSGi). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2023-54344",
      "detail": "EXPLOIT PUBLISHED — CVE-2023-54344 (Eclipse Equinox OSGi). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2024-58304",
      "detail": "EXPLOIT PUBLISHED — CVE-2024-58304 (SPA-CART CMS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2024-58387",
      "detail": "EXPLOIT PUBLISHED — CVE-2024-58387 (Inspur Haiyue HCM Cloud). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-62593",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-62593 (ray-project ray). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-100891",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-100891 (Trusted Domain Project OpenDMARC). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-100894",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-100894 (mathurvishal CloudClassroom-PHP-Project). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-100900",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-100900 (DevaslanPHP project-management). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-100903",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-100903 (ООО НПО Ритм GEOritm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-100907",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-100907 (Eyeplus). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-101000",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-101000 (Netcore NBR100V2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-101009",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-101009 (aaPanel BaoTa). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-101012",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-101012 (mathurvishal CloudClassroom-PHP-Project). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-101015",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-101015 (Trusted Domain Project OpenDMARC). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-101018",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-101018 (dayrui XunruiCMS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-101037",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-101037 (FAST FAC1200R). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-101040",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-101040 (Ricoh SP 330DN). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-101054",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-101054 (Thinkware U3000). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-101067",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-101067 (dbgate). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-101070",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-101070 (dbgate). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-101073",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-101073 (Netcore NR289-GE). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-101076",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-101076 (Netcore NR289-GE). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-101079",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-101079 (agentverus-scanner). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-101132",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-101132 (deepseek-harness). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-101142",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-101142 (Eleveo Quality Management). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-101145",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-101145 (Eleveo Call Recording Software). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-101188",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-101188 (Netcore POWER13). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-101261",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-101261 (Ziroom ZHOME A0101). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-101264",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-101264 (Ziroom ZHOME A0101). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-101278",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-101278 (Trusted Domain Project OpenDMARC). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-101281",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-101281 (Trusted Domain Project OpenDMARC). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-101859",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-101859 (raspap-webgui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-101878",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-101878 (bitwarden server). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-102241",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-102241 (Netcore NAP930). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-102245",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-102245 (MODSetter SurfSense). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-102249",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-102249 (REBUILD). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-102361",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-102361 (gz-yami mall4j). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-102365",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-102365 (gz-yami mall4j). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-102373",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-102373 (GestSup). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-102507",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-102507 (BishopFox sliver). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-102793",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-102793 (Ziroom ZHOME A0101). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-102805",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-102805 (Nothings stb). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-103113",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-103113 (OS4ED openSIS-Classic). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-11553",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-11553 (Tenda HG7). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-22681",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-22681 (Volcengine OpenViking). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-43641",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-43641 (Softaculous Virtualizor). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-43642",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-43642 (Softaculous Virtualizor). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-43643",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-43643 (Softaculous Virtualizor). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44402",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44402 (Voltronic Power SNMP Web Pro). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48710",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48710 (Kludex starlette). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-57517",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-57517 (Control Web Panel). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-57863",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-57863 (crater-invoice-inc crater). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58143",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58143 (Cotonti). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58144",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58144 (Cotonti). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-6958",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-6958 (Invicti Security Corp. Acunetix). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-7006",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-7006 (Sublime HQ Pty Ltd Sublime Text 4). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71503",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71503 (dolibarr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71504",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71504 (dolibarr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71505",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71505 (dolibarr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71506",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71506 (dolibarr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71507",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71507 (dolibarr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71508",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71508 (dolibarr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71509",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71509 (dolibarr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71510",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71510 (dolibarr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71511",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71511 (dolibarr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-72708",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-72708 (SPIP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-72709",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-72709 (SPIP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-72710",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-72710 (SPIP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73678",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73678 (MindsDB Minds Platform). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73693",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73693 (FileRun). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73694",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73694 (FileRun). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73698",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73698 (FileRun). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73699",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73699 (FileRun). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-74038",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-74038 (wazuh-manager). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-74039",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-74039 (wazuh-manager). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-74044",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-74044 (wazuh-manager). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-74046",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-74046 (wazuh-manager). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-80112",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-80112 (PassMark Software PerformanceTest). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-80113",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-80113 (PassMark Software PerformanceTest). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-80114",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-80114 (PassMark Software PerformanceTest). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-80115",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-80115 (PassMark Software PerformanceTest). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-80116",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-80116 (PassMark Software PerformanceTest). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-80118",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-80118 (PassMark Software PerformanceTest). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-80119",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-80119 (PassMark Software PerformanceTest). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82017",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82017 (IGEL OS 12). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82524",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82524 (unopim). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82536",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82536 (RooCodeInc Roo-Code). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82537",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82537 (RooCodeInc Roo-Code). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-93339",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-93339 (Metaphor Creations Ditty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-93353",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-93353 (9001 copyparty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-93355",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-93355 (BerriAI litellm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-95290",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-95290 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-95295",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-95295 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-95300",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-95300 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-95301",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-95301 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-95330",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-95330 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-95342",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-95342 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-95344",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-95344 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-95358",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-95358 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-95362",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-95362 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-95364",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-95364 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-95366",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-95366 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-95370",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-95370 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-95375",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-95375 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-95376",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-95376 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-95675",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-95675 (D-LINK DAP-1360). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-88771",
      "detail": "DUE DATE PASSED — CVE-2026-88771 (Citrix NetScaler ADC). CISA remediation deadline was September 30, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-88772",
      "detail": "DUE DATE PASSED — CVE-2026-88772 (Citrix NetScaler ADC). CISA remediation deadline was September 30, 2026; still in catalog."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2013-0431",
      "detail": "RESCORED — CVE-2013-0431. CVSS 5.3 → 3.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2015-3246",
      "detail": "RESCORED — CVE-2015-3246. CVSS 5.1 → 7.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2021-22175",
      "detail": "RESCORED — CVE-2021-22175 (GitLab). CVSS 6.8 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2023-27351",
      "detail": "RESCORED — CVE-2023-27351 (PaperCut NG). CVSS 8.2 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-7399",
      "detail": "RESCORED — CVE-2024-7399 (Samsung Electronics MagicINFO 9 Server). CVSS 8.8 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-9379",
      "detail": "RESCORED — CVE-2024-9379 (Ivanti CSA (Cloud Services Appliance)). CVSS 6.5 → 7.2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-100268",
      "detail": "RESCORED — CVE-2026-100268 (JetBrains YouTrack). CVSS 7.7 → 2.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-10031",
      "detail": "RESCORED — CVE-2026-10031 (drakkan SFTPGo). CVSS 2.3 → 5.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-102578",
      "detail": "RESCORED — CVE-2026-102578 (moodle). CVSS 5.5 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-102580",
      "detail": "RESCORED — CVE-2026-102580 (moodle). CVSS 2.2 → 4.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-102581",
      "detail": "RESCORED — CVE-2026-102581 (moodle). CVSS 4.6 → 5.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-102582",
      "detail": "RESCORED — CVE-2026-102582 (moodle). CVSS 2.2 → 4.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-102586",
      "detail": "RESCORED — CVE-2026-102586 (moodle). CVSS 4.3 → 6.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-81438",
      "detail": "RESCORED — CVE-2026-81438 (Dell OpenManage Server Administrator Managed Node (Patch) for Windows). CVSS 3.7 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-81439",
      "detail": "RESCORED — CVE-2026-81439 (Dell OpenManage Server Administrator Managed Node (Patch) for Windows). CVSS 3.7 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-81440",
      "detail": "RESCORED — CVE-2026-81440 (Dell OpenManage Server Administrator Managed Node (Patch) for Windows). CVSS 7.3 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-81441",
      "detail": "RESCORED — CVE-2026-81441 (Dell OpenManage Server Administrator Managed Node (Patch) for Windows). CVSS 4 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-81475",
      "detail": "RESCORED — CVE-2026-81475 (Dell OpenManage Server Administrator Managed Node (Patch) for Windows). CVSS 8.1 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-81476",
      "detail": "RESCORED — CVE-2026-81476 (Dell OpenManage Server Administrator Managed Node (Patch) for Windows). CVSS 8.1 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-84440",
      "detail": "RESCORED — CVE-2026-84440 (IBM Guardium Data Protection). CVSS 7.5 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-94184",
      "detail": "RESCORED — CVE-2026-94184 (Red Hat Enterprise Linux 10). CVSS 8.1 → 5.3 (NVD)."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-14441",
      "detail": "PATCH SHIPPED — CVE-2026-14441 (Brocade SANnav). Fixed in SANnav 3.1.0a."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-14442",
      "detail": "PATCH SHIPPED — CVE-2026-14442 (Brocade SANnav). Fixed in SANnav 3.1.0a."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-14443",
      "detail": "PATCH SHIPPED — CVE-2026-14443 (Brocade SANnav). Fixed in SANnav before 3.0.1.a."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-79654",
      "detail": "PATCH SHIPPED — CVE-2026-79654 (Red Hat Satellite 6.16 for RHEL 8). Fixed in Red Hat Satellite 6.16 for RHEL 8 0:4.14.0.23-1.el8sat."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-82368",
      "detail": "PATCH SHIPPED — CVE-2026-82368 (Brocade SANnav). Fixed in SANnav 3.0.1a."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-82369",
      "detail": "PATCH SHIPPED — CVE-2026-82369 (Brocade SANnav). Fixed in SANnav 3.0.1a."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-82370",
      "detail": "PATCH SHIPPED — CVE-2026-82370 (Brocade SANnav). Fixed in SANnav 3.0.1a."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-82371",
      "detail": "PATCH SHIPPED — CVE-2026-82371 (Brocade SANnav). Fixed in SANnav 3.0.1a."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-82372",
      "detail": "PATCH SHIPPED — CVE-2026-82372 (Brocade SANnav). Fixed in SANnav 3.0.1."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
