{
  "day": "2026-10-02",
  "boundary": "UTC calendar day",
  "published_count": 398,
  "by_severity": {
    "CRITICAL": 29,
    "HIGH": 178,
    "MEDIUM": 150,
    "LOW": 17
  },
  "kev_count": 0,
  "exploit_reference_count": 0,
  "awaiting_enrichment_count": 24,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-15896",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00883,
      "epss_percentile": 0.5776,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebRehab",
      "product": "Super Forms – Drag & Drop Form Builder",
      "cwe": "CWE-26",
      "title": "Super Forms <= 6.3.316 - Unauthenticated Path Traversal to Arbitrary File Read via 'sfgtfi' URL Path Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15896"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-97637",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00636,
      "epss_percentile": 0.48656,
      "kev": false,
      "kev_due_at": null,
      "vendor": "parorrey",
      "product": "JSON API Auth",
      "cwe": "CWE-287",
      "title": "JSON API Auth <= 3.1.2 - Unauthenticated Authentication Bypass via Cached 'generate_auth_cookie' Response",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97637"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-92174",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00565,
      "epss_percentile": 0.44914,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gpriday",
      "product": "SiteOrigin Widgets Bundle",
      "cwe": "CWE-98",
      "title": "SiteOrigin Widgets Bundle <= 1.73.2 - Authenticated (Contributor+) Local File Inclusion via 'theme' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92174"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-92820",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00518,
      "epss_percentile": 0.41975,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SaturdayDrive",
      "product": "Ninja Forms - File Uploads",
      "cwe": "CWE-434",
      "title": "Ninja Forms - File Uploads <= 3.3.34 - Unauthenticated Arbitrary File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92820"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-94541",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00492,
      "epss_percentile": 0.40089,
      "kev": false,
      "kev_due_at": null,
      "vendor": "amauric",
      "product": "WPMobile.App – Android and iOS App Builder",
      "cwe": "CWE-862",
      "title": "WPMobile.App <= 11.82 - Unauthenticated Admin Account Takeover via 'wpapp_category[]' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94541"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-14378",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00479,
      "epss_percentile": 0.39106,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dplugins",
      "product": "DevKit Pro",
      "cwe": "CWE-287",
      "title": "DevKit Pro <= 2.3.0 - Unauthenticated Authentication Bypass to Administrator Account Takeover via 'original_user_id' Cookie in Frontend Revert Switch Flow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14378"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-63567",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00467,
      "epss_percentile": 0.38202,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "bc-csharp",
      "cwe": "CWE-203",
      "title": "IesEngine block-cipher mode checks padding before MAC (CBC padding oracle)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63567"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-93698",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00464,
      "epss_percentile": 0.3794,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webpros",
      "product": "cPanel",
      "cwe": "CWE-78",
      "title": "Insufficient validation allows arbitrary commands to be executed via the Multilang adminbin.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93698"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-97652",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00461,
      "epss_percentile": 0.37689,
      "kev": false,
      "kev_due_at": null,
      "vendor": "veronalabs",
      "product": "WP Statistics – Simple, privacy-friendly Google Analytics alternative",
      "cwe": "CWE-79",
      "title": "WP Statistics <= 14.16.14 - Reflected Cross-Site Scripting via REQUEST_URI Query-Parameter Key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97652"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-17508",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00436,
      "epss_percentile": 0.35604,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-JAVA",
      "cwe": "CWE-770",
      "title": "Password-based KDF cost parameters honoured unbounded from untrusted input across the remaining PBE entry points",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17508"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-80298",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0043,
      "epss_percentile": 0.34954,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HAVELSAN Inc.",
      "product": "Sef - AI Chatbot Platform",
      "cwe": "CWE-89",
      "title": "SQL Injection in HAVELSAN's Sef - AI Chatbot Platform",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80298"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-94635",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00426,
      "epss_percentile": 0.34593,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-130",
      "title": "Apache Thrift: Lua `TBinaryProtocol:readMessageBegin` bypasses `checkStringSize` on the pre-versioned name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94635"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-94639",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00426,
      "epss_percentile": 0.34592,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-248",
      "title": "Apache Thrift: Java `TSaslNonblockingServer`: residual of CVE-2026-61373 (thread-death black hole + no cross-connection budget)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94639"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-87920",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00419,
      "epss_percentile": 0.33895,
      "kev": false,
      "kev_due_at": null,
      "vendor": "boldgrid",
      "product": "W3 Total Cache",
      "cwe": "CWE-79",
      "title": "W3 Total Cache <= 2.10.6 - Unauthenticated Stored Cross-Site Scripting via Comment Content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87920"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-103603",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00412,
      "epss_percentile": 0.33136,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "bc-csharp",
      "cwe": "CWE-789",
      "title": "Unbounded HSS public key level count allows huge array allocation during signature verification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103603"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-93029",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00401,
      "epss_percentile": 0.32005,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webpros",
      "product": "cPanel",
      "cwe": "CWE-79",
      "title": "There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Manage SSL Hosts interface.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93029"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-93697",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00401,
      "epss_percentile": 0.32005,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webpros",
      "product": "cPanel",
      "cwe": "CWE-79",
      "title": "There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93697"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-19660",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00397,
      "epss_percentile": 0.31515,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DiviEngine",
      "product": "Divi Membership",
      "cwe": "CWE-287",
      "title": "Divi Membership <= 2.3.0 - Unauthenticated Authentication Bypass via 'paypal_param' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19660"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-104480",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00397,
      "epss_percentile": 0.31565,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Discord",
      "product": "libdave",
      "cwe": "CWE-390",
      "title": "Improper MLS Welcome roster validation in Discord libdave allows unauthorized group membership",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104480"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-63569",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00396,
      "epss_percentile": 0.31424,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "bc-csharp",
      "cwe": "CWE-20",
      "title": "MTI/A0 DHAgreement does not validate the peer's ephemeral value",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63569"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-59659",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00396,
      "epss_percentile": 0.31462,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Repasat",
      "product": "Repasat application",
      "cwe": "CWE-79",
      "title": "Multiple vulnerabilities in the Repasat application",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59659"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-59660",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00396,
      "epss_percentile": 0.31463,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Repasat",
      "product": "Repasat application",
      "cwe": "CWE-79",
      "title": "Multiple vulnerabilities in the Repasat application",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59660"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-59661",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00396,
      "epss_percentile": 0.31463,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Repasat",
      "product": "Repasat application",
      "cwe": "CWE-79",
      "title": "Multiple vulnerabilities in the Repasat application",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59661"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-95662",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00396,
      "epss_percentile": 0.3146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Repasat",
      "product": "Repasat application",
      "cwe": "CWE-79",
      "title": "Multiple vulnerabilities in the Repasat application",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95662"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-59672",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00379,
      "epss_percentile": 0.29575,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Repasat",
      "product": "Repasat application",
      "cwe": "CWE-79",
      "title": "Multiple vulnerabilities in the Repasat application",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59672"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-59673",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00379,
      "epss_percentile": 0.29574,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Repasat",
      "product": "Repasat application",
      "cwe": "CWE-79",
      "title": "Multiple vulnerabilities in the Repasat application",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59673"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-63566",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00371,
      "epss_percentile": 0.28734,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "bc-csharp",
      "cwe": "CWE-789",
      "title": "DTLS handshake reassembler allocates buffer from unchecked 24-bit length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63566"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-85492",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00368,
      "epss_percentile": 0.2834,
      "kev": false,
      "kev_due_at": null,
      "vendor": "smub",
      "product": "All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)",
      "cwe": "CWE-79",
      "title": "All in One SEO <= 5.0.1.1 - Reflected DOM-Based Cross-Site Scripting via URL Pathname",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85492"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-104403",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00339,
      "epss_percentile": 0.25053,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThimPress",
      "product": "LearnPress",
      "cwe": "CWE-639",
      "title": "WordPress LearnPress plugin <= 4.4.9 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104403"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-63572",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0033,
      "epss_percentile": 0.23861,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "bc-csharp",
      "cwe": "CWE-770",
      "title": "Unbounded MAC and bag-decryption iteration counts when loading PKCS#12 files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63572"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-63578",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0033,
      "epss_percentile": 0.23861,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "bc-csharp",
      "cwe": "CWE-770",
      "title": "Unbounded PBE iteration count when decrypting PKCS#8 private keys",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63578"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-104123",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00329,
      "epss_percentile": 0.23762,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Online Reviewer Management System",
      "cwe": "CWE-74",
      "title": "SourceCodester Online Reviewer Management System btn_functions.php activity sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104123"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-94405",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00325,
      "epss_percentile": 0.23284,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shahjada",
      "product": "Download Manager",
      "cwe": "CWE-639",
      "title": "WordPress Download Manager plugin <= 3.3.71 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94405"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-17507",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.23155,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-JAVA",
      "cwe": "CWE-195",
      "title": "MLS membership checks compare a uint32 leaf_index as signed, admitting an out-of-range sender",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17507"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-63568",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00319,
      "epss_percentile": 0.22577,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "bc-csharp",
      "cwe": "CWE-770",
      "title": "Unbounded CMP/CRMF password-based MAC iteration count allows CPU exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63568"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-10026",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00318,
      "epss_percentile": 0.22507,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CTX",
      "product": "CTX Feed Pro",
      "cwe": "CWE-94",
      "title": "CTX Feed Pro <= 7.6.12 - Authenticated (Administrator+) Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10026"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-63574",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00315,
      "epss_percentile": 0.22206,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "bc-csharp",
      "cwe": "CWE-789",
      "title": "Unbounded allocation from OpenPGP signature and user attribute subpacket lengths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63574"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-103600",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00315,
      "epss_percentile": 0.22206,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "bc-csharp",
      "cwe": "CWE-674",
      "title": "Unbounded ASN.1 nesting depth causes process-terminating stack overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103600"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-59669",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00315,
      "epss_percentile": 0.22197,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Repasat",
      "product": "Repasat application",
      "cwe": "CWE-79",
      "title": "Multiple vulnerabilities in the Repasat application",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59669"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-63573",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00308,
      "epss_percentile": 0.21395,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "bc-csharp",
      "cwe": "CWE-203",
      "title": "Bleichenbacher padding oracle in CMS RSA PKCS#1 v1.5 key-transport unwrap",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63573"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-100107",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00307,
      "epss_percentile": 0.21291,
      "kev": false,
      "kev_due_at": null,
      "vendor": "extendthemes",
      "product": "Kubio AI Page Builder",
      "cwe": "CWE-79",
      "title": "Kubio AI Page Builder <= 2.9.2 - Unauthenticated Stored Cross-Site Scripting via SVG Comment Content (KSES Allowlist Bypass)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100107"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-100182",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00307,
      "epss_percentile": 0.21291,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpchill",
      "product": "Download Monitor",
      "cwe": "CWE-79",
      "title": "Download Monitor <= 5.2.10 - Unauthenticated Stored Cross-Site Scripting via Cross-Origin postMessage to Admin Editor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100182"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-102565",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00307,
      "epss_percentile": 0.21291,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bookingalgorithms",
      "product": "BA Book Everything",
      "cwe": "CWE-79",
      "title": "BA Book Everything <= 1.8.28 - Unauthenticated Stored Cross-Site Scripting via 'booking_service_qty' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102565"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-102772",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00307,
      "epss_percentile": 0.21292,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jtsternberg",
      "product": "CMB2",
      "cwe": "CWE-79",
      "title": "CMB2 <= 2.13.1 - Unauthenticated Stored Cross-Site Scripting via 'textarea_code' Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102772"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-12951",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00307,
      "epss_percentile": 0.21336,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wcmp",
      "product": "MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions",
      "cwe": "CWE-89",
      "title": "MultiVendorX <= 5.0.18 - Authenticated (Store Manager+) SQL Injection via 'order_by' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12951"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-15897",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.20924,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebRehab",
      "product": "Super Forms – Drag & Drop Form Builder",
      "cwe": "CWE-269",
      "title": "Super Forms – Drag & Drop Form Builder <= 6.3.316 - Authenticated (Subscriber+) Privilege Escalation via 'user_id' Parameter in Register & Login",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15897"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-90438",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00292,
      "epss_percentile": 0.19789,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kstover",
      "product": "Ninja Forms – Contact Form Builder with Calculators, Quizzes, Signatures & AI Form Builder",
      "cwe": "CWE-79",
      "title": "Ninja Forms <= 3.15.4 - Unauthenticated Stored Cross-Site Scripting via Paragraph Text (RTE) Field Submission",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90438"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-104120",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00288,
      "epss_percentile": 0.1939,
      "kev": false,
      "kev_due_at": null,
      "vendor": "modelcontextprotocol",
      "product": "mcp-server-fetch",
      "cwe": "CWE-918",
      "title": "modelcontextprotocol mcp-server-fetch/mcp-server-everything Fetch Tool server.py fetch_url server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104120"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-59670",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00288,
      "epss_percentile": 0.19438,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Repasat",
      "product": "Repasat application",
      "cwe": "CWE-79",
      "title": "Multiple vulnerabilities in the Repasat application",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59670"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-59671",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00288,
      "epss_percentile": 0.19437,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Repasat",
      "product": "Repasat application",
      "cwe": "CWE-79",
      "title": "Multiple vulnerabilities in the Repasat application",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59671"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-103601",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00286,
      "epss_percentile": 0.19121,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "bc-csharp",
      "cwe": "CWE-354",
      "title": "CcmBlockCipher and KCcmBlockCipher leave unverified plaintext in the output buffer after a failed tag check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103601"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-97336",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00285,
      "epss_percentile": 0.1903,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jtsternberg",
      "product": "CMB2",
      "cwe": "CWE-79",
      "title": "CMB2 <= 2.13.0 - Unauthenticated Stored Cross-Site Scripting via 'file_list' Field Type",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97336"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-102002",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00285,
      "epss_percentile": 0.1907,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themeisle",
      "product": "Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE",
      "cwe": "CWE-200",
      "title": "Otter Blocks <= 3.2.6 - Authenticated (Subscriber+) Sensitive Information Exposure in Form Submissions Dashboard Widget",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102002"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-18036",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00282,
      "epss_percentile": 0.1876,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-JAVA",
      "cwe": "CWE-208",
      "title": "NTRU leaks private key information by reducing secret values with a non-constant-time integer division",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18036"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-97634",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00281,
      "epss_percentile": 0.18687,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stellarwp",
      "product": "Event Tickets and Registration",
      "cwe": "CWE-89",
      "title": "Event Tickets and Registration <= 5.29.5 - Authenticated (Contributor+) SQL Injection via 'orderby' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97634"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-94180",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00281,
      "epss_percentile": 0.18661,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Monetizemore",
      "product": "Advanced Ads",
      "cwe": "CWE-639",
      "title": "WordPress Advanced Ads plugin <= 2.0.26 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94180"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-80464",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00274,
      "epss_percentile": 0.17987,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HAVELSAN Inc.",
      "product": "Sef - AI Chatbot Platform",
      "cwe": "CWE-918",
      "title": "API Tool Runner SSRF in HAVELSAN's Sef - AI Chatbot Platform",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80464"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-96566",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00271,
      "epss_percentile": 0.17563,
      "kev": false,
      "kev_due_at": null,
      "vendor": "satollo",
      "product": "Newsletter – Send awesome emails from WordPress",
      "cwe": "CWE-79",
      "title": "Newsletter <= 9.4.0 - Unauthenticated Stored Cross-Site Scripting via 'np1' Custom Field Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96566"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-93756",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.17095,
      "kev": false,
      "kev_due_at": null,
      "vendor": "smub",
      "product": "Smash Balloon Social Post Feed – Simple Social Feeds for WordPress",
      "cwe": "CWE-79",
      "title": "Smash Balloon Social Post Feed <= 4.13.0 - Unauthenticated Stored Cross-Site Scripting via Facebook Comment Message in Admin Builder Preview",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93756"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-94432",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00266,
      "epss_percentile": 0.17038,
      "kev": false,
      "kev_due_at": null,
      "vendor": "latepoint",
      "product": "Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress",
      "cwe": "CWE-639",
      "title": "Appointment Booking Plugin <= 5.7.1 - Insecure Direct Object Reference to Unauthenticated Unauthorized Transaction Intent Creation/Modification and Invoice Enumeration via 'invoice_id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94432"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-91020",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00264,
      "epss_percentile": 0.16601,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WebToffee Gift Cards for WooCommerce",
      "cwe": "CWE-472",
      "title": "WebToffee Gift Cards for WooCommerce < 1.3.1 - Unauthenticated Gift Card Amount Manipulation via wt_credit_amount",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91020"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-103604",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00259,
      "epss_percentile": 0.15924,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "bc-csharp",
      "cwe": "CWE-407",
      "title": "Quadratic-time escaping when converting X.509 distinguished names to strings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103604"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-96567",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00259,
      "epss_percentile": 0.15943,
      "kev": false,
      "kev_due_at": null,
      "vendor": "websoudan",
      "product": "MW WP Form",
      "cwe": "CWE-79",
      "title": "MW WP Form <= 5.1.7 - Unauthenticated Stored Cross-Site Scripting via 'post_id' Parameter (via stored form-submitted post meta)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96567"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-16000",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00252,
      "epss_percentile": 0.15192,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "bc-csharp",
      "cwe": "CWE-325",
      "title": "KCcmBlockCipher (DSTU 7624 CCM) tag not bound to nonce when no associated data is used",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16000"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-96578",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0025,
      "epss_percentile": 0.14762,
      "kev": false,
      "kev_due_at": null,
      "vendor": "creative-solutions-1",
      "product": "GSpeech TTS – WordPress Text To Speech Plugin",
      "cwe": "CWE-79",
      "title": "GSpeech TTS <= 3.22.0 - Unauthenticated Stored Cross-Site Scripting via Comment Content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96578"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-13413",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00247,
      "epss_percentile": 0.14503,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "CMP – Coming Soon & Maintenance",
      "cwe": "CWE-284",
      "title": "CMP - Coming Soon & Maintenance < 4.1.20 - Unauthenticated Maintenance Mode Bypass via Login URL Match",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13413"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-103602",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00243,
      "epss_percentile": 0.14105,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "bc-csharp",
      "cwe": "CWE-295",
      "title": "Name constraints bypass via trailing dot in rfc822Name, dNSName and URI hosts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103602"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-95670",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00241,
      "epss_percentile": 0.13832,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mihdan",
      "product": "No External Links",
      "cwe": "CWE-79",
      "title": "No External Links <= 5.2.0 - Unauthenticated Stored Cross-Site Scripting via Log URL via /goto/{base64} Redirect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95670"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-96871",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00241,
      "epss_percentile": 0.13831,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kitae-park",
      "product": "Mang Board",
      "cwe": "CWE-79",
      "title": "Mang Board <= 2.4.2 - Unauthenticated Stored Cross-Site Scripting via 'data_type' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96871"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-97342",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00241,
      "epss_percentile": 0.13831,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jetmonsters",
      "product": "JetFormBuilder — Dynamic Blocks Form Builder",
      "cwe": "CWE-79",
      "title": "JetFormBuilder <= 3.6.5.4 - Unauthenticated Stored Cross-Site Scripting via 'choice' Post Meta via Insert/Update Post Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97342"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-97641",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00241,
      "epss_percentile": 0.13829,
      "kev": false,
      "kev_due_at": null,
      "vendor": "comesio",
      "product": "Relevanssi – A Better Search",
      "cwe": "CWE-79",
      "title": "Relevanssi <= 4.28.3 - Unauthenticated Stored Cross-Site Scripting via Comment Content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97641"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-97663",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00241,
      "epss_percentile": 0.13829,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ivole",
      "product": "Customer Reviews for WooCommerce",
      "cwe": "CWE-79",
      "title": "Customer Reviews for WooCommerce <= 5.122.0 - Unauthenticated Stored Cross-Site Scripting via Comment Author Name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97663"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-63577",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00236,
      "epss_percentile": 0.13191,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "bc-csharp",
      "cwe": "CWE-295",
      "title": "Name Constraints bypass: directoryName constraint matched at any position in the DN instead of as a prefix",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63577"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-95817",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00236,
      "epss_percentile": 0.13283,
      "kev": false,
      "kev_due_at": null,
      "vendor": "apasionados",
      "product": "DoFollow Case by Case",
      "cwe": "CWE-79",
      "title": "DoFollow Case by Case <= 3.6.0 - Unauthenticated Stored Cross-Site Scripting via Comment Content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95817"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-90987",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00236,
      "epss_percentile": 0.13246,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Easy PayPal & Stripe Buy Now Button",
      "cwe": "CWE-472",
      "title": "Easy PayPal & Stripe Buy Now Button 1.8 - 2.0.5 - Unauthenticated Payment Amount Manipulation via Client-Supplied Price",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90987"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-90952",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.13118,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Edit Password Protected",
      "cwe": "CWE-862",
      "title": "WP Edit Password Protected 2.0.0 - 2.0.6 - Unauthenticated Site-Wide Access Mode Bypass via REST API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90952"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-103426",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00231,
      "epss_percentile": 0.12713,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Relevanssi",
      "product": "Relevanssi Premium",
      "cwe": "CWE-79",
      "title": "Relevanssi Premium <= 2.31.4 - Unauthenticated Stored Cross-Site Scripting via '_rt' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103426"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-15999",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00227,
      "epss_percentile": 0.12222,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "bc-csharp",
      "cwe": "CWE-354",
      "title": "AES-CCM decryption accepts zero or out-of-range tag length, bypassing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15999"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-84740",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00223,
      "epss_percentile": 0.11697,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "The Events Calendar",
      "cwe": "CWE-74",
      "title": "The Events Calendar 6.12.0 - 6.17.5 - Unauthenticated Arbitrary Shortcode Execution via 'view_data' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84740"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-85005",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.11656,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Popup Maker WP",
      "cwe": "CWE-862",
      "title": "Popup Maker WP 1.2.2.1 - 1.4.5 - Subscriber+ Zero-Argument PHP Callable Invocation via Missing Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85005"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-78471",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.11507,
      "kev": false,
      "kev_due_at": null,
      "vendor": "optimizingmatters",
      "product": "Autoptimize",
      "cwe": "CWE-79",
      "title": "Autoptimize <= 3.1.15.1 - Unauthenticated Stored Cross-Site Scripting via Comment Author Name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78471"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-63576",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00218,
      "epss_percentile": 0.11109,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "bc-csharp",
      "cwe": "CWE-295",
      "title": "URI name constraints checked against a mis-parsed host",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63576"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-1661",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00218,
      "epss_percentile": 0.11059,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Mail Logging",
      "cwe": "CWE-79",
      "title": "WP Mail Logging < 1.17.0 - Unauthenticated HTML Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1661"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-97338",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00216,
      "epss_percentile": 0.1088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "codename065",
      "product": "Download Manager",
      "cwe": "CWE-79",
      "title": "Download Manager <= 3.3.70 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Display Name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97338"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-63570",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00213,
      "epss_percentile": 0.10558,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "bc-csharp",
      "cwe": "CWE-835",
      "title": "Pkcs12Store.GetCertificateChain loops forever on cyclic issuer links",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63570"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-93880",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.103,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpsoul",
      "product": "Greenshift – animation and page builder blocks",
      "cwe": "CWE-79",
      "title": "Greenshift <= 13.2.0 - Reflected Cross-Site Scripting via '{{GET:}}' Dynamic Placeholder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93880"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-80337",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0021,
      "epss_percentile": 0.10231,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HAVELSAN Inc.",
      "product": "Sef - AI Chatbot Platform",
      "cwe": "CWE-862",
      "title": "Unauthorized Cross-Chatbot Tool Invocation in HAVELSAN's Sef - AI Chatbot Platform",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80337"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-104054",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00209,
      "epss_percentile": 0.10119,
      "kev": false,
      "kev_due_at": null,
      "vendor": "calcom",
      "product": "cal.diy",
      "cwe": "CWE-862",
      "title": "calcom cal.diy PBAC Permission BookingAccessService.ts doesUserIdHaveAccessToBooking authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104054"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-96647",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.08999,
      "kev": false,
      "kev_due_at": null,
      "vendor": "webilia",
      "product": "Listdom: AI-powered Business Directory with Classifieds Ads Listings",
      "cwe": "CWE-79",
      "title": "Listdom: AI-powered Business Directory with Classifieds Ads Listings <= 6.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'lsd[remark]' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96647"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-104052",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.0893,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Pet Shop Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Pet Shop Management System admin_reject_completed.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104052"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-104053",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.08931,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Pet Shop Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Pet Shop Management System admin_reservefilter.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104053"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-93367",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00194,
      "epss_percentile": 0.08207,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wp-buy",
      "product": "Visitor Traffic Real Time Statistics pro",
      "cwe": "CWE-79",
      "title": "Visitors Traffic Real Time Statistics Pro <= 11.22 - Unauthenticated Stored Cross-Site Scripting via ahcpro_track_visitor (page_title)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93367"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-63575",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00194,
      "epss_percentile": 0.08167,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "bc-csharp",
      "cwe": "CWE-835",
      "title": "PKCS#12 key derivation loops about 2^32 times on a zero or negative iteration count",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63575"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-102731",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00193,
      "epss_percentile": 0.08132,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Directory LDAP API",
      "cwe": "CWE-789",
      "title": "Apache Directory LDAP API: Denial of service via excessive memory allocation in BER decode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102731"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-79618",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00185,
      "epss_percentile": 0.07324,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP User Frontend",
      "cwe": "CWE-862",
      "title": "WP User Frontend < 4.3.12 - Subscriber+ Post Creation via Subscription-Gated Form",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79618"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-97219",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00185,
      "epss_percentile": 0.07323,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MStore API",
      "cwe": "CWE-862",
      "title": "MStore API 4.21.1 - 4.22.0 - Subscriber+ Payment Bypass via 'status' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97219"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-92924",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00183,
      "epss_percentile": 0.07101,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Unlimited Elements for Elementor",
      "cwe": "CWE-74",
      "title": "Unlimited Elements For Elementor < 2.0.21 - Subscriber+ Arbitrary Shortcode Execution via get_addon_output_data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92924"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-103552",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00181,
      "epss_percentile": 0.0696,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Directory LDAP API",
      "cwe": "CWE-121",
      "title": "Apache Directory LDAP API: A unbound client can send a deeply nested search filter that overflows the stack in the server's decoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103552"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-91828",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.06289,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy.",
      "cwe": "CWE-400",
      "title": "OMGF < 6.3.11 - Unauthenticated DoS via do_optimize",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91828"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-16001",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00173,
      "epss_percentile": 0.06023,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "bc-csharp",
      "cwe": "CWE-354",
      "title": "IesEngine stream-mode MAC forgery via length-dependent KDF split",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16001"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-95512",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00172,
      "epss_percentile": 0.05946,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Hardened Images",
      "cwe": "CWE-400",
      "title": "Freetype: freetype: denial of service via repeated subroutine allocations in cid font loader",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95512"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-63571",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00169,
      "epss_percentile": 0.05619,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "bc-csharp",
      "cwe": "CWE-347",
      "title": "Attribute certificate path validation does not verify the attribute certificate's signature",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63571"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-84925",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00168,
      "epss_percentile": 0.05544,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeFusion",
      "product": "Avada | Website Builder For WordPress & WooCommerce",
      "cwe": "CWE-79",
      "title": "Avada | Website Builder For WordPress & WooCommerce <= 7.16.1 - Reflected Cross-Site Scripting via 'lang' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84925"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-80443",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00163,
      "epss_percentile": 0.04957,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HAVELSAN Inc.",
      "product": "Sef - AI Chatbot Platform",
      "cwe": "CWE-295",
      "title": "Insecure TLS Certificate Validation in API Tool Runner in HAVELSAN's Sef - AI Chatbot Platform",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80443"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-103098",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00161,
      "epss_percentile": 0.04608,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GV-Eye",
      "cwe": "CWE-319",
      "title": "GV-Eye Sensitive information exposure in URL query parameter Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103098"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-94298",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00158,
      "epss_percentile": 0.04344,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "BuildKit",
      "cwe": "CWE-89",
      "title": "BuildKit < 1.0.29 - Contributor+ Stored SQLi via list_content Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94298"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-91784",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00154,
      "epss_percentile": 0.03922,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cjbassi",
      "product": "gotop",
      "cwe": "CWE-88",
      "title": "Argument Injection leading to arbitrary process termination in gotop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91784"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-103096",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00152,
      "epss_percentile": 0.03743,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GV-Eye",
      "cwe": "CWE-312",
      "title": "GV-Eye Hardcoded API Key Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103096"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-103097",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00152,
      "epss_percentile": 0.03743,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GV-Eye",
      "cwe": "CWE-312",
      "title": "GV-Eye Relay Payment API Key Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103097"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-13718",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.03745,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Tabs Responsive",
      "cwe": "CWE-79",
      "title": "Tabs Responsive <= 2.5 - Shop Manager+ Stored XSS via WooCommerce Product Tab Content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13718"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-85016",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.03745,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Unlimited Elements for Elementor",
      "cwe": "CWE-79",
      "title": "Unlimited Elements For Elementor < 2.0.21 - Contributor+ Stored XSS via Icon Library Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85016"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-91022",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.03745,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Motors",
      "cwe": "CWE-79",
      "title": "Motors < 1.4.124 - Listing Manager+ Stored XSS via Badge Color",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91022"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-90988",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.03245,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Request a Quote",
      "cwe": "CWE-200",
      "title": "Request a Quote <= 2.5.6 - Unauthenticated Quote Request Contact Record Disclosure via emd_get_std_pagenum",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90988"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-97317",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.02758,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Giveaways and Contests by RafflePress",
      "cwe": "CWE-200",
      "title": "Giveaways and Contests by RafflePress < 1.12.27 - Unauthenticated reCAPTCHA Secret Key Disclosure via Giveaway Page",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97317"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-97318",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.02561,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Giveaways and Contests by RafflePress",
      "cwe": "CWE-601",
      "title": "Giveaways and Contests by RafflePress < 1.12.27 - Unauthenticated Stored Open Redirect via 'parent_url' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97318"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-81740",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.02561,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Paytm Payment Gateway",
      "cwe": "CWE-287",
      "title": "Paytm Payment Gateway < 2.8.9 - Unauthenticated Order Status Manipulation via Payment Callback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81740"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-85004",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.02328,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Popup Maker",
      "cwe": "CWE-284",
      "title": "Popup Maker WP <= 1.4.5 - Subscriber+ Missing Authorization via sgpm_connect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85004"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-91023",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00132,
      "epss_percentile": 0.02327,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Motors",
      "cwe": "CWE-862",
      "title": "Motors – Car Dealership & Classified Listings < 1.4.124 - Subscriber+ Cross-User Post Meta Modification via stm_make_featured",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91023"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-21140",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00105,
      "epss_percentile": 0.00987,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Mobile Devices",
      "cwe": null,
      "title": "Improper access control in ManagedProvisioning prior to SMR Sep-2026 Release 1 allows local attackers to install arbitrary applications.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21140"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-103956",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "loom",
      "cwe": "CWE-306",
      "title": "Missing authentication for critical function in Loom for AWS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103956"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-90970",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab AI Gateway",
      "cwe": "CWE-1336",
      "title": "Improper Neutralization of Special Elements Used in a Template Engine in GitLab AI Gateway",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90970"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-19652",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DiviEngine",
      "product": "Divi Membership",
      "cwe": "CWE-269",
      "title": "Divi Membership <= 2.2.0 - Unauthenticated Privilege Escalation via 'form_id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19652"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-104846",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lxsmnsyc",
      "product": "seroval",
      "cwe": "CWE-843",
      "title": "Seroval: `fromJSON()` Promise thenable assimilation invokes plugin-produced callables (bypass of CVE-2026-59940)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104846"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-103628",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-787",
      "title": "Out of bounds write in WebGL in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103628"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-104848",
      "cvss_base": 9.5,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tinylibs",
      "product": "tinypool",
      "cwe": "CWE-1321",
      "title": "Tinypool: Prototype Pollution gadget in worker options leads to Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104848"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-104849",
      "cvss_base": 9.5,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tinylibs",
      "product": "tinypool",
      "cwe": "CWE-94",
      "title": "Tinypool: Prototype Pollution Gadget to RCE in run() options",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104849"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-75937",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Digi International",
      "product": "IX Family",
      "cwe": "CWE-78",
      "title": "OS Command Injection in Digi Accelerated Linux (DAL OS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75937"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-86325",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Moxa",
      "product": "MGate MB3170 Series",
      "cwe": "CWE-121",
      "title": "A stack-based buffer overflow vulnerability exists in protocol gateways' account management interface. The vulnerability is caused by insufficient length validation of the `account_name` parameter when processing account management requests. An attacker authenticated as a read-only user to the web management interface could supply a specially crafted account name that exceeds the size of the internal stack buffer, resulting in corruption of program execution flow. Successful exploitation could allow an attacker to read sensitive information from device memory, including credentials, modify arbitrary memory contents, and disrupt device availability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86325"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2023-54405",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "H3C",
      "product": "CVM",
      "cwe": "CWE-434",
      "title": "H3C CVM Unauthenticated File Upload via fileUpload/upload Token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-54405"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-82042",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "UTMStack",
      "product": "UTMStack",
      "cwe": "CWE-306",
      "title": "UTMStack < 11.2.16 Authentication Bypass via InternalApiKeyFilter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82042"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-84411",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MikroTik",
      "product": "RouterOS",
      "cwe": "CWE-191",
      "title": "MikroTik RouterOS Integer Underflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84411"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-95102",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Monta",
      "product": "monta.app",
      "cwe": "CWE-306",
      "title": "Monta monta.app Missing Authentication for Critical Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95102"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-104019",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "sagemaker-distribution",
      "cwe": "CWE-78",
      "title": "OS command injection in the Studio Space startup validation script in Amazon SageMaker Distribution when running on Amazon SageMaker Unified Studio",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104019"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-104610",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "HG7",
      "cwe": "CWE-119",
      "title": "Tenda HG7/HG9/HG10 Boa Web Server formLoopBack boaGetVar stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104610"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-83632",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-122",
      "title": "Apache Thrift: C++ THttpTransport grows its line buffer without bound",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83632"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-91135",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-122",
      "title": "Apache Thrift: C++ `THeaderTransport::transform()` heap buffer overflow (write direction)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91135"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-104467",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-862",
      "title": "YesWiki before 4.6.7 Authorization Bypass via Public API Mode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104467"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-103648",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "demsking",
      "product": "image-downloader",
      "cwe": "CWE-22",
      "title": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in image-downloader",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103648"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-39718",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webriti",
      "product": "Wallstreet",
      "cwe": "CWE-352",
      "title": "WordPress Wallstreet theme <= 2.8.6 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39718"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-96940",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Exchange Server 2016 Cumulative Update 23",
      "cwe": "CWE-1390",
      "title": "Microsoft Exchange Server Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96940"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-103622",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103622"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-103625",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "title": "Type confusion in V8 in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103625"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-104445",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-290",
      "title": "YesWiki before 4.6.7 Authentication Bypass via ActivityPub Inbox Actor Spoofing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104445"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-104457",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-89",
      "title": "YesWiki before 4.6.7 SQL Injection via filtertags filterN parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104457"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-104462",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-89",
      "title": "YesWiki before 4.6.7 SQL Injection via nuagetag tags parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104462"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-104464",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-918",
      "title": "YesWiki before 4.6.7 SSRF via Bazar abonnements sync actor parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104464"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-104851",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fsspec",
      "product": "filesystem_spec",
      "cwe": "CWE-94",
      "title": "fsspec: Server-Side Template Injection in ReferenceFileSystem leads to Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104851"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2014-125130",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Damjan",
      "product": "CodeArt Google MP3 Audio Player",
      "cwe": "CWE-22",
      "title": "CodeArt Google MP3 Audio Player 1.0.11 Arbitrary File Read via direct_download.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2014-125130"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2020-37278",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Weaver",
      "product": "e-Bridge",
      "cwe": "CWE-918",
      "title": "Weaver e-Bridge Unauthenticated Arbitrary File Read via saveYZJFile",
      "url": "https://www.cve.org/CVERecord?id=CVE-2020-37278"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-61373",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-770",
      "title": "Apache Thrift: Java TSaslNonblockingServer pre-auth unbounded SASL frame allocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61373"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-63772",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-770",
      "title": "Apache Thrift: Unauthenticated single-packet crash of Go Thrift servers via the THeader transform count",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63772"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-66081",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-824",
      "title": "Apache Thrift: c_glib read_message_begin leaves output parameters unset for non-versioned messages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66081"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-66837",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-121",
      "title": "Apache Thrift: PHP accelerator sizes a stack buffer from a wire-controlled string length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66837"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-66858",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-674",
      "title": "Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: skip() does not apply the recursion limit (Python accelerator, PHP, Perl, Lua, Smalltalk, OCaml)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66858"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-66859",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-457",
      "title": "Apache Thrift: c_glib multiplexed processor crashes on a message it cannot route",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66859"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-82039",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "UTMStack",
      "product": "UTMStack",
      "cwe": "CWE-89",
      "title": "UTMStack < 11.2.16 SQL Injection via searchGroupsByFilter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82039"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-82458",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-770",
      "title": "Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: Container element count not bounded by the bytes available",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82458"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-83663",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-674",
      "title": "Apache Thrift: TFramedTransport and THeaderTransport re-enter Read once per frame that carries no payload (Go)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83663"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-83745",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-130",
      "title": "Apache Thrift, Apache Thrift: WebSocket frame decoders allocate the payload buffer from the declared length, not the bytes received (Node.js, D)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83745"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-85493",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-248",
      "title": "Apache Thrift, Apache Thrift: TProtocolUtil.skip follows peer-chosen nesting to any depth the stack allows (Dart, Java ME)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85493"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-85494",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-130",
      "title": "Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: Framed transport and binary protocol size read buffers from a peer-declared length without a limit (multi-language)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85494"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-86535",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-835",
      "title": "Apache Thrift: A JSON member name can stall the Node server's event loop indefinitely",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86535"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-86537",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-191",
      "title": "Apache Thrift: A truncated HTTP request stops the D library's server, allowing an unauthenticated remote attacker to deny service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86537"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-87117",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-476",
      "title": "Apache Thrift: PHP `thrift_protocol` accelerator dereferences a missing container-element spec",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87117"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-91137",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-770",
      "title": "Apache Thrift: PHP `thrift_protocol` accelerator: zero-byte container elements",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91137"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-93925",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-121",
      "title": "Apache Thrift: C++ `THeaderTransport::writeVarint32()` stack buffer overflow on a negative protocol id",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93925"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-93926",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-401",
      "title": "Apache Thrift: C++ `THeaderTransport::untransform()` leaks the zlib stream on the error path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93926"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-94422",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "xdg-dbus-proxy",
      "cwe": "CWE-290",
      "title": "xdg-dbus-proxy: message filtering bypass via reply serial allows sandbox escape",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94422"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-94633",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-130",
      "title": "Apache Thrift: Dart `TBinaryProtocol.readMessageBegin` allocates from the pre-versioned name length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94633"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-94642",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-248",
      "title": "Apache Thrift: PHP `TSimpleServer` exits the whole process on any non-transport exception",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94642"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-94646",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-248",
      "title": "Apache Thrift: Node.js `server.js` ends the process on any per-connection error (+ two triggers)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94646"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-94658",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-407",
      "title": "Apache Thrift: Lua `TFramedTransport`/`THttpTransport` re-slice the buffer on every read (quadratic)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94658"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-96277",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-248",
      "title": "Apache Thrift: Ruby `SimpleServer` ends `serve()` on any non-Transport/Protocol exception",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96277"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-96294",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-248",
      "title": "Apache Thrift: nodejs web server: no `error` listener on an upgraded WebSocket connection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96294"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-97363",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Monta",
      "product": "monta.app",
      "cwe": "CWE-307",
      "title": "Monta monta.app Improper Restriction of Excessive Authentication Attempts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97363"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-104410",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-862",
      "title": "SiYuan before 3.8.5 Information Disclosure via /api/export/preview",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104410"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-104422",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZcashFoundation",
      "product": "zebra",
      "cwe": "CWE-345",
      "title": "Zebra before 6.3.0 Block Sync Denial of Service via Coinbase scriptSig Rewrite",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104422"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-104423",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZcashFoundation",
      "product": "zebra",
      "cwe": "CWE-405",
      "title": "Zebra before 6.2.1 Denial of Service via Uncapped V6 Shielded Proof Verification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104423"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-104430",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZcashFoundation",
      "product": "zebra",
      "cwe": "CWE-628",
      "title": "Zebra 4.5.0 Consensus Split via P2SH Sigop Overcount",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104430"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-104431",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZcashFoundation",
      "product": "zebra",
      "cwe": "CWE-405",
      "title": "Zebra before 6.0.0 Denial of Service via Synchronous Script FFI Verification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104431"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-104433",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kvcache-ai",
      "product": "Mooncake",
      "cwe": "CWE-125",
      "title": "Mooncake before 0.3.12 Out-of-Bounds Read via P2P Handshake readString",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104433"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-104438",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-862",
      "title": "YesWiki before 4.6.7 Information Disclosure via listpagestag and includepages Actions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104438"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-104460",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-89",
      "title": "YesWiki before 4.6.7 Unauthenticated Blind SQL Injection via newtextsearch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104460"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-104472",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-862",
      "title": "YesWiki before 4.6.7 Missing Authorization via Attachment Download Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104472"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-86326",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Moxa",
      "product": "MGate MB3170 Series",
      "cwe": "CWE-347",
      "title": "An improper verification of cryptographic signature vulnerability exists in protocol gateways because the device does not properly verify the cryptographic authenticity of firmware images before installation. An attacker with high privileges and access to the firmware update interface could provide a specially crafted or modified firmware image, causing it to be installed on the device. Successful exploitation could allow the attacker to execute unauthorized code, compromise the integrity and availability of the device, and persist malicious modifications across subsequent firmware updates.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86326"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-94591",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Armatura LLC",
      "product": "Armatura One",
      "cwe": "CWE-321",
      "title": "Armatura LLC Armatura One Use of Hard-coded Cryptographic Key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94591"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-94592",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Armatura LLC",
      "product": "Armatura One",
      "cwe": "CWE-798",
      "title": "Armatura LLC Armatura One Use of Hard-coded Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94592"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-104414",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-79",
      "title": "Ghost from 2.5.0 before 6.64.0 Stored XSS via oEmbed Photo Responses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104414"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-104418",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-22",
      "title": "Ghost from 6.10.3 before 6.64.0 RCE via Theme Translation Files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104418"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-104471",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-434",
      "title": "YesWiki before 4.6.7 Unrestricted File Upload via Bazar CSV Import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104471"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-94593",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Armatura LLC",
      "product": "Armatura One",
      "cwe": "CWE-532",
      "title": "Armatura LLC Armatura One Insertion of Sensitive Information into Log File",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94593"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-104411",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-79",
      "title": "Ghost 6.22.1 before 6.64.0 Stored XSS via Local Storage File Uploads",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104411"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-104413",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-79",
      "title": "Ghost 5.94.0 before 6.64.0 Stored XSS via Bookmark Card Images",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104413"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-104611",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "AC9",
      "cwe": "CWE-119",
      "title": "Tenda AC9 POST Request fast_setting_internet_set stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104611"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-104847",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ProseMirror",
      "product": "prosemirror-view",
      "cwe": "CWE-79",
      "title": "ProseMirror: XSS vulnerability in prosemirror-view's paste handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104847"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-104854",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nrwl",
      "product": "nx",
      "cwe": "CWE-269",
      "title": "Nx daemon and plugin worker sockets are accessible to other local users",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104854"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-94483",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vercel",
      "product": "next.js",
      "cwe": "CWE-918",
      "title": "Next.js: Server-Side Request Forgery in Image Optimization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94483"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-103958",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "loom",
      "cwe": "CWE-918",
      "title": "Server-side request forgery in the tool server and remote agent connection handling in Loom for AWS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103958"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-104435",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZcashFoundation",
      "product": "zebra",
      "cwe": "CWE-347",
      "title": "Zebra 4.4.0 Consensus Divergence via V5 SIGHASH_SINGLE Without Output",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104435"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-104437",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZcashFoundation",
      "product": "zebra",
      "cwe": "CWE-347",
      "title": "Zebra before 4.4.0 Consensus Split via SIGHASH_SINGLE Missing-Output Handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104437"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-104449",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-639",
      "title": "YesWiki before 4.6.7 Unauthenticated Page Overwrite via Bazar id_fiche",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104449"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-104458",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-918",
      "title": "YesWiki before 4.6.7 SSRF Guard Bypass via IPv6 Transition Addresses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104458"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-104463",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-918",
      "title": "YesWiki before 4.6.7 Unauthenticated SSRF via ActivityPub Inbox",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104463"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-66055",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-770",
      "title": "Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TJSONProtocol accepts a single JSON string/number exceeding the configured size limit (multi-language)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66055"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-82459",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-191",
      "title": "Apache Thrift: Integer underflow in C++ THeaderTransport allows an unauthenticated remote peer to terminate a 32-bit process",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82459"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-85476",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-835",
      "title": "Apache Thrift: c_glib `read_all` spins when the underlying read returns 0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85476"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-90440",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-248",
      "title": "Apache Thrift: An exception escaping a libevent callback stops the D library's non-blocking server, allowing an unauthenticated remote attacker to deny service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90440"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-94634",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-770",
      "title": "Apache Thrift: Python `TJSONProtocol` has a string length limit that is off by default",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94634"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-94636",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-409",
      "title": "Apache Thrift: Python `TZlibTransport` stops enforcing its decompressed-size limit once the limit is exactly used up",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94636"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-94637",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-409",
      "title": "Apache Thrift: Go `THeaderTransport` does not bound the inflated size of a ZLIB frame",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94637"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-94644",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-770",
      "title": "Apache Thrift: PHP `TJSONProtocol` string/number readers have no size bound",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94644"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-94645",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-770",
      "title": "Apache Thrift: Node.js `TJSONProtocol` uses a peer-declared container size as an unbounded loop bound",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94645"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-94648",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-770",
      "title": "Apache Thrift: dart `TJsonProtocol`/`TJSONProtocol` has no string size bound",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94648"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-94650",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-674",
      "title": "Apache Thrift: c_glib generated struct readers have no recursion-depth guard (native stack exhaustion)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94650"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-94651",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-755",
      "title": "Apache Thrift: Java `TSaslNonblockingServer` `Computation.run` orphans a connection on a pre-auth parse error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94651"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-94653",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-407",
      "title": "Apache Thrift: PHP framed/memory/HTTP transports re-slice the buffer on every read (quadratic)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94653"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-94654",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-835",
      "title": "Apache Thrift: Python `TNonblockingServer` busy-loops and stops selecting all fds after an 8192-byte-boundary frame",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94654"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-94655",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-407",
      "title": "Apache Thrift: Lua `TJsonProtocol` string/number readers have no size bound and are quadratic",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94655"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-94656",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-770",
      "title": "Apache Thrift: rb `TJsonProtocol`/`TJSONProtocol` has no string size bound",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94656"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-94657",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-770",
      "title": "Apache Thrift: javame `TJsonProtocol`/`TJSONProtocol` has no string size bound",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94657"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-96286",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-248",
      "title": "Apache Thrift: Perl servers end `serve()` when serving one connection fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96286"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-96287",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-407",
      "title": "Apache Thrift: Perl `FramedTransport` reads and TLS socket writes re-slice the remaining buffer on every call (quadratic)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96287"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-96288",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-674",
      "title": "Apache Thrift: Erlang generated struct reads have no recursion-depth guard (unbounded memory)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96288"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-96289",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-674",
      "title": "Apache Thrift: php `--gen php:inlined` struct readers (and `TProtocol::skipBinary`) have no recursion-depth guard",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96289"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-96292",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-407",
      "title": "Apache Thrift: Lua `THttpTransport:_parseHeaders` matches each header line with a backtracking pattern (quadratic)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96292"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-96990",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-770",
      "title": "Apache Thrift: Erlang thrift_json_protocol reads a whole message with no size bound",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96990"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-103957",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "loom",
      "cwe": "CWE-201",
      "title": "Server-side request forgery in the OAuth2 discovery handling in Loom for AWS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103957"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-104426",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZcashFoundation",
      "product": "zebra",
      "cwe": "CWE-407",
      "title": "Zebra before 6.1.0 Quadratic Complexity DoS via Block Transparent Value Check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104426"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-104427",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZcashFoundation",
      "product": "zebra",
      "cwe": "CWE-459",
      "title": "Zebra before 6.1.0 Chain Stall via Stale parent_error_map Entry",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104427"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-104450",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-79",
      "title": "YesWiki before 4.6.7 ACL Bypass and Stored XSS via pointimage Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104450"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-104476",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "backdrop",
      "product": "backdrop",
      "cwe": "CWE-200",
      "title": "Backdrop CMS before 1.35.1 Information Disclosure via Configuration Export Archive",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104476"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-51907",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-22",
      "title": "In TaskingAI v0.3.0 in the QR Code Generator plugin save_base64_image function, a path traversal vulnerability allows attackers to write image files to arbitrary locations on the server filesystem by manipulating the project_id parameter.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51907"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-104988",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Certificate System 10",
      "cwe": "CWE-290",
      "title": "Pki-core: dogtag-pki: redhat-pki: pki: est fullcmc authentication bypass allows certificate mis-issuance with arbitrary subject",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104988"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-104026",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Meta Platforms, Inc",
      "product": "Sapling SCM",
      "cwe": "CWE-150",
      "title": "In Sapling SCM prior to v0.2.20260929-102736, control characters were allowed to be embedded in Git subtree URLs. A maliciously constructed repository, if cloned by a target, could trigger code execution on otherwise read-only actions such as sl log/blame/annotate.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104026"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-104416",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-203",
      "title": "Ghost 4.39.0 before 6.64.0 Invite Token Disclosure via Admin API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104416"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-104469",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-384",
      "title": "YesWiki before 4.6.7 Session Fixation via Login in AuthController.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104469"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-104873",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "langchain-ai",
      "product": "langgraph",
      "cwe": "CWE-863",
      "title": "LangGraph SDK custom auth silently ignores actions= on resource decorators",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104873"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-51916",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-284",
      "title": "TransformerOptimus SuperAGI v0.0.14 contains an incorrect access control vulnerability in delete_user_knowledge in superagi/controllers/knowledges.py. In affected source snapshots, POST /knowledges/delete/{knowledge_id} deletes the selected knowledge object without requiring authentication in the route and without verifying organization ownership of the supplied knowledge_id.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51916"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-67989",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-1333",
      "title": "crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in Mistral model capability matching on Ruby 3.1.x",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67989"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-104845",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lxsmnsyc",
      "product": "seroval",
      "cwe": "CWE-770",
      "title": "Seroval: Memory exhaustion via unchecked TypedArray length in JSON deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104845"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-104861",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nodeca",
      "product": "probe-image-size",
      "cwe": "CWE-400",
      "title": "probe-image-size: Quadratic-time Denial of Service in the SVG Parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104861"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-104733",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ProcessOne",
      "product": "ejabberd",
      "cwe": "CWE-290",
      "title": "User Impersonation/Authorization Bypass in XMPP Server ejabberd",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104733"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-104859",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nrwl",
      "product": "nx",
      "cwe": "CWE-78",
      "title": "Nx: OS command injection in the @nx/docker release pipeline",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104859"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-93875",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Crocoblock",
      "product": "JetAppointment",
      "cwe": "CWE-79",
      "title": "JetAppointment <= 2.5.2.1 - Unauthenticated Stored Cross-Site Scripting via 'friendlyTime' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93875"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-102626",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LimeSurvey",
      "product": "LimeSurvey",
      "cwe": "CWE-79",
      "title": "LimeSurvey Community Edition 7.4.0 - Stored XSS through the Date/Time date_min question attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102626"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-104443",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-863",
      "title": "YesWiki before 4.6.7 Scope Bypass via Triples Delete API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104443"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-104448",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-352",
      "title": "YesWiki before 4.6.7 CSRF Page Deletion via ajaxdeletepage Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104448"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-104456",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-89",
      "title": "YesWiki before 4.6.7 Second-Order SQL Injection via ACL Username",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104456"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-61374",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-770",
      "title": "Apache Thrift: Java TSaslTransport post-auth data-frame missing size limit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61374"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-82045",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "UTMStack",
      "product": "UTMStack",
      "cwe": "CWE-89",
      "title": "UTMStack < 11.2.16 JPQL Injection via searchPropertyValues",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82045"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-85215",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GG Soft Software Services Inc.",
      "product": "Paperwork",
      "cwe": "CWE-89",
      "title": "SQL Injection in GG Soft's Paperwork",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85215"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-96613",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Meari",
      "product": "IoT Cloud Platform OpenAPI Service",
      "cwe": "CWE-862",
      "title": "Missing Authorization in Meari IoT Cloud Platform OpenAPI Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96613"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-104434",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZcashFoundation",
      "product": "zebra",
      "cwe": "CWE-617",
      "title": "Zebra before 8.0.0 Denial of Service via z_listunifiedreceivers RPC",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104434"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-104439",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-204",
      "title": "YesWiki before 4.6.7 User Enumeration via Lost-Password Flow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104439"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-104444",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-639",
      "title": "YesWiki before 4.6.7 Authorization Bypass via Comments API editComment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104444"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-104447",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-352",
      "title": "YesWiki before 4.6.7 CSRF Package Deletion via autoupdate UpdateAction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104447"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-104478",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getformwork",
      "product": "formwork",
      "cwe": "CWE-22",
      "title": "Formwork before 2.3.13 Path Traversal via BackupController Download and Delete",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104478"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-104908",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-285",
      "title": "MISP Decaying Model Import Mass Assignment Allows Cross-Organization Model Overwrite and Default Flagging",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104908"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-104912",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-284",
      "title": "MISP Correlation Authorization Bypass Exposes Restricted Event and Attribute Data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104912"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-104991",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Alanaktion",
      "product": "phproject",
      "cwe": "CWE-862",
      "title": "Phproject < 1.8.7 Missing Authorization via Issues REST API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104991"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-105050",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PeaZip",
      "product": "PeaZip",
      "cwe": "CWE-180",
      "title": "PeaZip before 11.3.0, in a non-default configuration, is vulnerable to OS command injection via a filename in an archive because \"quotation character already used in the string\" is mishandled.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105050"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-102795",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Traffic Server",
      "cwe": "CWE-284",
      "title": "Apache Traffic Server: SNI to Host header matching policy is not properly enforced",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102795"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-66054",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-409",
      "title": "Apache Thrift: C++ THeaderTransport does not enforce configured maxFrameSize",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66054"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-66331",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-770",
      "title": "Apache Thrift: Buffered transport reads are not accounted against MaxMessageSize",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66331"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-82043",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "UTMStack",
      "product": "UTMStack",
      "cwe": "CWE-204",
      "title": "UTMStack < 11.2.16 Account Enumeration via Password Reset Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82043"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-85086",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-295",
      "title": "Apache Thrift: Perl TLS client disables certificate verification by default",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85086"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-85087",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-295",
      "title": "Apache Thrift: Python ≥3.12 host-name check silently becomes a no-op",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85087"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-85088",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-295",
      "title": "Apache Thrift, Apache Thrift: The C++ and D clients fall back to the certificate Common Name when subjectAltName entries are present but do not match",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85088"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-93474",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Monta",
      "product": "monta.app",
      "cwe": "CWE-522",
      "title": "Monta monta.app Insufficiently Protected Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93474"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-97212",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Monta",
      "product": "monta.app",
      "cwe": "CWE-613",
      "title": "Monta monta.app Insufficient Session Expiration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97212"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-103762",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-862",
      "title": "SiYuan before v3.8.5 Missing Authorization in Save-Path Resolver Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103762"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-103763",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-200",
      "title": "SiYuan before v3.8.5 Information Disclosure via /api/notebook/getNotebookInfo",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103763"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-104417",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-22",
      "title": "Ghost 1.20.0 before 6.64.0 Path Traversal via Locale Setting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104417"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-104420",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZcashFoundation",
      "product": "zebra",
      "cwe": "CWE-704",
      "title": "Zebra before 6.3.0 Peer Misbehavior Ban Bypass via Gossiped Blocks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104420"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-104421",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZcashFoundation",
      "product": "zebra",
      "cwe": "CWE-459",
      "title": "Zebra before 6.2.1 Block Download Denial of Service via KnownBlock SentHashes Lockout",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104421"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-104425",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZcashFoundation",
      "product": "zebra",
      "cwe": "CWE-405",
      "title": "Zebra before 6.1.0 Batch-Verification Poisoning DoS via Unattributed Pushed Transactions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104425"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-104428",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZcashFoundation",
      "product": "zebra",
      "cwe": "CWE-617",
      "title": "Zebra before 11.0.0 Denial of Service via getblock Verbosity 2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104428"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-104429",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZcashFoundation",
      "product": "zebra",
      "cwe": "CWE-770",
      "title": "Zebra before 6.0.0-rc.0 Per-Peer Mempool Admission Bypass via P2P tx Messages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104429"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-104432",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZcashFoundation",
      "product": "zebra",
      "cwe": "CWE-754",
      "title": "Zebra before 6.3.0 False Readiness via Discarded One-Hash FindBlocks Response",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104432"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-104440",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-918",
      "title": "YesWiki before 4.6.7 Blind SSRF via bazarlist API idtypeannonce Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104440"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-104441",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-918",
      "title": "YesWiki before 4.6.7 Unauthenticated SSRF via valeur Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104441"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-104442",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-918",
      "title": "YesWiki before 4.6.7 Unauthenticated SSRF via syndication Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104442"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-104446",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-306",
      "title": "YesWiki before 4.6.7 Unauthenticated Open Mail Relay via Contact Mail Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104446"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-104454",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-1333",
      "title": "YesWiki before 4.6.7 ReDoS via wakka.php Edit-Preview Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104454"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-104455",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-200",
      "title": "YesWiki before 4.6.7 Read-ACL Bypass via recentchangesrssplus RSS Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104455"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-104459",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-918",
      "title": "YesWiki before 4.6.7 SSRF via ActivityPub WebFinger actor_handle",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104459"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-105030",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rajnandan1",
      "product": "kener",
      "cwe": "CWE-200",
      "title": "Kener 4.0.0 before 4.1.6 Hidden Monitor Data Disclosure via Dashboard API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105030"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-19856",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "All in One SEO",
      "cwe": null,
      "title": "All in One SEO < 5.0.2.1 - Unauthenticated Arbitrary Shortcode Execution via Search Query",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19856"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-32585",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "airano",
      "product": "Airano MCP Bridge",
      "cwe": "CWE-862",
      "title": "WordPress Airano MCP Bridge plugin <= 2.11.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32585"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-39439",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kiera Howe",
      "product": "WebSamurai",
      "cwe": "CWE-862",
      "title": "WordPress WebSamurai plugin <= 1.0.7 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39439"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-82041",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "UTMStack",
      "product": "UTMStack",
      "cwe": "CWE-862",
      "title": "UTMStack < 11.2.16 Missing Authorization via Command WebSocket",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82041"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-85209",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AVEZ Electronics Communication Training and Consultancy Trade Inc.",
      "product": "Learning Management System (LMS)",
      "cwe": "CWE-862",
      "title": "IDOR in AVEZ Electronics's LMS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85209"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-102798",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX Group",
      "product": "ThemeREX Addons",
      "cwe": "CWE-79",
      "title": "WordPress ThemeREX Addons plugin <= 2.46.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102798"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-103036",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "middleapi",
      "product": "orpc",
      "cwe": "CWE-915",
      "title": "@orpc/json-schema: Prototype injection in smart coercion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103036"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-103918",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "middleapi",
      "product": "orpc",
      "cwe": "CWE-915",
      "title": "@orpc/zod: Prototype injection in smart coercion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103918"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-97876",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU",
      "product": "grub2",
      "cwe": "CWE-822",
      "title": "Bypass of GRUB lockdown restriction in Secure Boot mode via serial command MMIO base address",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97876"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-102797",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX Group",
      "product": "ThemeREX Addons",
      "cwe": "CWE-918",
      "title": "WordPress ThemeREX Addons plugin <= 2.46.0 - Server Side Request Forgery (SSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102797"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-82044",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "UTMStack",
      "product": "UTMStack",
      "cwe": "CWE-918",
      "title": "UTMStack < 11.2.16 Server-Side Request Forgery via downloadPdf",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82044"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-85483",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-393",
      "title": "Apache Thrift: c_glib TZlibTransport reports a full read after a premature stream end",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85483"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-86536",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-1321",
      "title": "Apache Thrift, Apache Thrift, Apache Thrift: A map key from the wire can replace a decoded object's prototype in generated JavaScript",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86536"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-92834",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-393",
      "title": "Apache Thrift: C++ WebSocket server transport does not read a full request length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92834"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-94484",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vercel",
      "product": "next.js",
      "cwe": "CWE-524",
      "title": "Next.js: Cache poisoning in Next.js SSG/ISR rendering leads to cross-user content substitution and persistent denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94484"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-94485",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vercel",
      "product": "next.js",
      "cwe": "CWE-346",
      "title": "Next.js: Information disclosure in Next.js App Router metadata image routes via dynamicParams bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94485"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-94543",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vercel",
      "product": "next.js",
      "cwe": "CWE-524",
      "title": "Next.js: Cache poisoning of SSG and ISR pages in self-hosted Next.js applications",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94543"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-94544",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vercel",
      "product": "next.js",
      "cwe": "CWE-524",
      "title": "Next.js: Pending `use cache` fill can leak Draft Mode content into regular responses and persisted pages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94544"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-94638",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-770",
      "title": "Apache Thrift: PHP `thrift_protocol` C extension ignores the configured `maxStringSize`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94638"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-94652",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-401",
      "title": "Apache Thrift: C++ `TEvhttpServer` leaks its `RequestContext` when the processor throws before calling back",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94652"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-101104",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Meari",
      "product": "IoT Cloud Platform OpenAPI Service",
      "cwe": "CWE-862",
      "title": "Missing Authorization in Meari IoT Cloud Platform OpenAPI Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101104"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-104419",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZcashFoundation",
      "product": "zebra",
      "cwe": "CWE-345",
      "title": "Zebra before 6.3.0 Honest Peer Banning via Far-Ahead FindBlocks Hashes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104419"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-104424",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZcashFoundation",
      "product": "zebra",
      "cwe": "CWE-131",
      "title": "Zebra before 6.1.0 Incorrect Block Size Calculation in getblocktemplate",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104424"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-104436",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZcashFoundation",
      "product": "zebra",
      "cwe": "CWE-770",
      "title": "Zebra before 4.5.0 CPU Amplification via Uncapped getblocks/getheaders Locator Length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104436"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-104468",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-613",
      "title": "YesWiki before 4.6.7 Non-Expiring Password Reset Tokens via LostPasswordAction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104468"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-104721",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QOS.CH Sarl",
      "product": "Logback-classic",
      "cwe": "CWE-22",
      "title": "Logback: Incomplete protection against CVE-2026-19880",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104721"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-104871",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "angular",
      "product": "angular-cli",
      "cwe": "CWE-22",
      "title": "Angular SSR: Path Traversal to Sibling Directories in CommonEngine on Windows",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104871"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-104906",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-79",
      "title": "MISP TAXII Object Viewer Stored XSS via Unescaped JSON Output",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104906"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-104843",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "astral-sh",
      "product": "uv",
      "cwe": "CWE-22",
      "title": "uv: Path traversal on Windows through wheel extraction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104843"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-104844",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "postcss",
      "product": "postcss-selector-parser",
      "cwe": "CWE-400",
      "title": "PostCSS: Quadratic complexity in flat selector parsing allows CPU exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104844"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-104853",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nrwl",
      "product": "nx",
      "cwe": "CWE-22",
      "title": "Nx: Path traversal in nx migrate package-migrations extraction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104853"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-104872",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-telemetry",
      "product": "opentelemetry-js-contrib",
      "cwe": "CWE-532",
      "title": "Multiple @opentelemetry/instrumentation-* packages expose database username via unconditional db.user span attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104872"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-105049",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zilliz",
      "product": "Attu",
      "cwe": "CWE-306",
      "title": "Zilliz Attu before 3.0.0 has a Playground feature that does not require authentication for proxying arbitrary HTTP and HTTPS requests to URLs on the public internet.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105049"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-104609",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "onetwothreeneth",
      "product": "HospitalManagementSystem",
      "cwe": "CWE-74",
      "title": "onetwothreeneth HospitalManagementSystem edit_accounts.php get sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104609"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-104637",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "onetwothreeneth",
      "product": "HospitalManagementSystem",
      "cwe": "CWE-284",
      "title": "onetwothreeneth HospitalManagementSystem controller.php edit_patient unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104637"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-104638",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "onetwothreeneth",
      "product": "HospitalManagementSystem",
      "cwe": "CWE-287",
      "title": "onetwothreeneth HospitalManagementSystem sessions.php improper authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104638"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-39444",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PublishPress",
      "product": "PublishPress Series",
      "cwe": "CWE-639",
      "title": "WordPress PublishPress Series plugin <= 3.1.3 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39444"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-104474",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "litespeedtech",
      "product": "openlitespeed",
      "cwe": "CWE-367",
      "title": "OpenLiteSpeed before 1.9.3 Local Privilege Escalation via lsup.sh Auto-Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104474"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-11795",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Softtr Informatics Trading Limited Company",
      "product": "E-Commerce Pack",
      "cwe": "CWE-203",
      "title": "User Enumeration in Softtr's E-Commerce Pack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11795"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-12392",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canonical",
      "product": "MAAS",
      "cwe": null,
      "title": "RPC secret disclosure via vendor data endpoint in Canonical MAAS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12392"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-32584",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Chiranjit Hazarika",
      "product": "Smart One Click Setup – Complete Demo Import &amp; Export",
      "cwe": "CWE-201",
      "title": "WordPress Smart One Click Setup – Complete Demo Import &amp; Export plugin <= 1.4.3 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32584"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-82040",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "UTMStack",
      "product": "UTMStack",
      "cwe": "CWE-918",
      "title": "UTMStack < 11.2.16 SSRF via IdentityProviderService",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82040"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-104055",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canonical",
      "product": "postgresql-operator",
      "cwe": "CWE-532",
      "title": "Monitoring-user password logged in cleartext by postgres_exporter in postgresql VM charm",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104055"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-104412",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-269",
      "title": "Ghost 0.5.0 before 6.64.0 Privilege Escalation via Staff Role Assignment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104412"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-104451",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-352",
      "title": "YesWiki before 4.6.7 CSRF Page Revision Restore via RevisionsHandler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104451"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-104452",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-352",
      "title": "YesWiki before 4.6.7 CSRF Attachment Deletion via filemanager Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104452"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-104453",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-352",
      "title": "YesWiki before 4.6.7 CSRF Tag Deletion via admintag Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104453"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-104470",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-79",
      "title": "YesWiki before 4.6.7 SSRF and XSS via Bazar valeur Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104470"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-104477",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "showdownjs",
      "product": "showdown",
      "cwe": "CWE-79",
      "title": "Showdown through 2.1.0 XSS via unescaped quote in href and src attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104477"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-104874",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aio-libs",
      "product": "multidict",
      "cwe": "CWE-401",
      "title": "Multidict: Reference leak in CIMultiDict/MultiDict items-view union and subtraction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104874"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-104900",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-79",
      "title": "MISP Stored XSS via Unescaped Count Field Value in Remote Event Preview Index",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104900"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-104910",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-285",
      "title": "MISP Information Disclosure via Related Events Listing Bypassing Per-Event Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104910"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-104914",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-284",
      "title": "MISP: Soft-Deleted Attributes from Other Organizations Exposed via Attribute Search and Paginated View",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104914"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-105029",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "uvdesk",
      "product": "support-center-bundle",
      "cwe": "CWE-639",
      "title": "UVdesk support-center-bundle before 1.1.3.3 IDOR via rateTicket Ticket Rating Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105029"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-5782",
      "cvss_base": 5.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Loglama.net",
      "product": "TurkHotspot",
      "cwe": "CWE-79",
      "title": "Reflected XSS in Loglama.NET's TurkHotspot",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5782"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-94594",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Armatura LLC",
      "product": "Armatura One",
      "cwe": "CWE-532",
      "title": "Armatura LLC Armatura One Insertion of Sensitive Information into Log File",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94594"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-104461",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-79",
      "title": "YesWiki before 4.6.7 Stored XSS via Unsanitized SVG Upload in Bazar FileField",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104461"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-104465",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-79",
      "title": "YesWiki before 4.6.7 Reflected XSS via field Parameter in mail Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104465"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-104466",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-79",
      "title": "YesWiki before 4.6.7 Stored XSS via Wakka Markdown Image src Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104466"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2026-104473",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-79",
      "title": "YesWiki before 4.5.3 Multiple Reflected XSS via BazaR and listpages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104473"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-104475",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "idurar",
      "product": "idurar-erp-crm",
      "cwe": "CWE-79",
      "title": "IDURAR ERP CRM through 4.1.1 Stored XSS via SVG Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104475"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-104479",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mindstellar",
      "product": "shopclass",
      "cwe": "CWE-79",
      "title": "Shopclass before 6.2.0 Stored XSS via Listing Description Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104479"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-104901",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-79",
      "title": "MISP ID Translator: Unescaped Remote Event ID Enables Cross-Site Scripting via Linked Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104901"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-59662",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Repasat",
      "product": "Repasat application",
      "cwe": "CWE-79",
      "title": "Multiple vulnerabilities in the Repasat application",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59662"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-59663",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Repasat",
      "product": "Repasat application",
      "cwe": "CWE-79",
      "title": "Multiple vulnerabilities in the Repasat application",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59663"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2026-59664",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Repasat",
      "product": "Repasat application",
      "cwe": "CWE-79",
      "title": "Multiple vulnerabilities in the Repasat application",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59664"
    },
    {
      "rank": 354,
      "cve_id": "CVE-2026-59665",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Repasat",
      "product": "Repasat application",
      "cwe": "CWE-79",
      "title": "Multiple vulnerabilities in the Repasat application",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59665"
    },
    {
      "rank": 355,
      "cve_id": "CVE-2026-59666",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Repasat",
      "product": "Repasat application",
      "cwe": "CWE-79",
      "title": "Multiple vulnerabilities in the Repasat application",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59666"
    },
    {
      "rank": 356,
      "cve_id": "CVE-2026-59667",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Repasat",
      "product": "Repasat application",
      "cwe": "CWE-79",
      "title": "Multiple vulnerabilities in the Repasat application",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59667"
    },
    {
      "rank": 357,
      "cve_id": "CVE-2026-59668",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Repasat",
      "product": "Repasat application",
      "cwe": "CWE-79",
      "title": "Multiple vulnerabilities in the Repasat application",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59668"
    },
    {
      "rank": 358,
      "cve_id": "CVE-2026-104907",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-79",
      "title": "MISP: JavaScript Injection via Remote Tag ID in Event Preview Inline Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104907"
    },
    {
      "rank": 359,
      "cve_id": "CVE-2026-39600",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mehul Gohil",
      "product": "Aculect AI Companion",
      "cwe": "CWE-601",
      "title": "WordPress Aculect AI Companion plugin <= 0.8.1 - Unvalidated Redirects and Forwards vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39600"
    },
    {
      "rank": 360,
      "cve_id": "CVE-2026-39717",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThimPress",
      "product": "LearnPress",
      "cwe": "CWE-862",
      "title": "WordPress LearnPress plugin <= 4.4.9.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39717"
    },
    {
      "rank": 361,
      "cve_id": "CVE-2026-51899",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-284",
      "title": "In SuperAGI v0.0.14 and prior, controller endpoints (/api/agents/create, /api/agents/schedule, /api/agents/delete, /api/agents/edit_schedule, /api/agents/stop_schedule) allow authenticated users from one organization to create, schedule, edit, stop, and delete agents belonging to a different organization's project. The endpoints accept a project_id parameter but do not verify that the project belongs to the authenticated user's organization.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51899"
    },
    {
      "rank": 362,
      "cve_id": "CVE-2026-105046",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kentico",
      "product": "Xperience",
      "cwe": "CWE-425",
      "title": "Kentico Xperience 13 before 13.0.216 lacks object-level authorization checks for administration API endpoints.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105046"
    },
    {
      "rank": 363,
      "cve_id": "CVE-2026-105048",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zilliz",
      "product": "Attu",
      "cwe": "CWE-1289",
      "title": "The Playground feature of Zilliz Attu before 3.0.0 allows SSRF (proxying of requests to private IP addresses).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105048"
    },
    {
      "rank": 364,
      "cve_id": "CVE-2026-39601",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPdevelop",
      "product": "Booking Calendar",
      "cwe": "CWE-362",
      "title": "WordPress Booking Calendar plugin <= 11.8.4 - Race Condition vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39601"
    },
    {
      "rank": 365,
      "cve_id": "CVE-2026-105043",
      "cvss_base": 3.6,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MathWorks",
      "product": "Simulink",
      "cwe": "CWE-451",
      "title": "MathWorks Simulink before R2026b, when showing a crafted .slx file, can have blocks that are never visible in the Simulink Editor but will cause code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105043"
    },
    {
      "rank": 366,
      "cve_id": "CVE-2026-104994",
      "cvss_base": 2.5,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aquasec",
      "product": "Trivy",
      "cwe": "CWE-24",
      "title": "Trivy before 0.71.0 allows directory traversal in Terraform filesystem functions when they try to access pathnames above the scan root. The risk occurs when using misconf scanning on untrusted input (e.g., upon a third-party pull request that contains a Terraform configuration), if sensitive data can be found at those unintended pathnames, and an adversary can then view a sensitive data value within scan output.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104994"
    },
    {
      "rank": 367,
      "cve_id": "CVE-2026-94486",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vercel",
      "product": "next.js",
      "cwe": "CWE-346",
      "title": "Next.js: Information disclosure in the Next.js development server's Model Context Protocol endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94486"
    },
    {
      "rank": 368,
      "cve_id": "CVE-2026-104415",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-203",
      "title": "Ghost 0.7.2 before 6.64.0 Password Hash Ordering Disclosure via Admin API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104415"
    },
    {
      "rank": 369,
      "cve_id": "CVE-2026-104606",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Online Admission System Project",
      "cwe": "CWE-74",
      "title": "itsourcecode Online Admission System Project confirm.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104606"
    },
    {
      "rank": 370,
      "cve_id": "CVE-2026-104612",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Student Result Management System",
      "cwe": "CWE-79",
      "title": "SourceCodester Student Result Management System Announcement new_announcement.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104612"
    },
    {
      "rank": 371,
      "cve_id": "CVE-2026-104613",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeAstro",
      "product": "Simple Pharmacy Management System",
      "cwe": "CWE-74",
      "title": "CodeAstro Simple Pharmacy Management System view.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104613"
    },
    {
      "rank": 372,
      "cve_id": "CVE-2026-104614",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeAstro",
      "product": "Simple Pharmacy Management System",
      "cwe": "CWE-74",
      "title": "CodeAstro Simple Pharmacy Management System delete.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104614"
    },
    {
      "rank": 373,
      "cve_id": "CVE-2026-104625",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeAstro",
      "product": "Simple Loan Management System",
      "cwe": "CWE-74",
      "title": "CodeAstro Simple Loan Management System index.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104625"
    },
    {
      "rank": 374,
      "cve_id": "CVE-2026-104855",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bytecodealliance",
      "product": "wasmtime",
      "cwe": "CWE-362",
      "title": "Wasmtime: Preemption and traps during bulk operations enable breaking internal VM state",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104855"
    },
    {
      "rank": 375,
      "cve_id": "CVE-2026-105051",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Irdeto",
      "product": "Denuvo Anti-Tamper",
      "cwe": "CWE-348",
      "title": "Denuvo Anti-Tamper through 2026-03-04 allows bypass of a hypervisor presence check via CPUID interception (SimpleSvm.sys on AMD; hyperkd.sys and hyperhv.dll on Intel).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105051"
    },
    {
      "rank": 376,
      "cve_id": "CVE-2026-51898",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "sinaptik-ai pandas-ai 3.0.0 is vulnerable to Code Injection in CodeExecutor.execute.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51898"
    },
    {
      "rank": 377,
      "cve_id": "CVE-2026-51901",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "SuperAGI up to 0.0.14 is vulnerable to Incorrect Access Control. The agent execution controller endpoint /api/agentexecutions/schedule allows authenticated users from one organization to schedule existing agents belonging to a different organization without proper authorization checks. The endpoint accepts an agent_id parameter but does not verify that the agent belongs to the authenticated user's organization.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51901"
    },
    {
      "rank": 378,
      "cve_id": "CVE-2026-51904",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "SuperAGI up to v0.0.14 contains an improper access control vulnerability in the agent execution controller. In affected source snapshots, create_agent_execution and create_agent_run in superagi/controllers/agent_execution.py accept a caller-supplied agent_id and fail to verify that the referenced agent belongs to the authenticated user's organization. A remote authenticated attacker from one organization can create or start execution records for agents owned by another organization through /agentexecutions/add or /agentexecutions/add_run.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51904"
    },
    {
      "rank": 379,
      "cve_id": "CVE-2026-51906",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "In TaskingAI v0.3.0 in the DALL-E 3 image generation tool save_url_image function, a path traversal vulnerability allows attackers to write downloaded images to arbitrary locations on the server filesystem by manipulating the project_id parameter.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51906"
    },
    {
      "rank": 380,
      "cve_id": "CVE-2026-51911",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "vanna v2.0.2 contains a code injection vulnerability in VannaBase.get_plotly_figure (src/vanna/legacy/base/base.py). Depending on the exposed entry, an attacker can trigger attacker-controlled code or command execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51911"
    },
    {
      "rank": 381,
      "cve_id": "CVE-2026-51914",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "TransformerOptimus SuperAGI v0.0.14 is vulnerable to Incorrect Access Control in the agent template controller. In affected source snapshots, save_agent_as_template and publish_template in superagi/controllers/agent_template.py accept caller-supplied agent_id or agent_execution_id values and do not verify that the referenced agent or execution belongs to the authenticated user's organization.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51914"
    },
    {
      "rank": 382,
      "cve_id": "CVE-2026-51915",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "TransformerOptimus SuperAGI v0.0.14 is vulnerable to Incorrect Access Control in the tool controller. In affected source snapshots, get_tool and update_tool in superagi/controllers/tool.py accept a caller-supplied tool_id and fail to verify organization ownership through the associated toolkit. A remote authenticated attacker from one organization can read or modify another organization's tool metadata through /tools/get/{tool_id} and /tools/update/{tool_id}.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51915"
    },
    {
      "rank": 383,
      "cve_id": "CVE-2026-51917",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "FinRobot v1.0.0 is vulnerable to Code Injection in CodingUtils.modify_code.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51917"
    },
    {
      "rank": 384,
      "cve_id": "CVE-2026-51918",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "FinRobot 1.0.0 contains code injection in CodingUtils.create_file_with_code ().",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51918"
    },
    {
      "rank": 385,
      "cve_id": "CVE-2026-51922",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "agentscope v1.0.20 contains code injection in execute_shell_command (src/agentscope/tool/_coding/_shell.py). Depending on the exposed entry, an attacker can trigger attacker-controlled code or command execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51922"
    },
    {
      "rank": 386,
      "cve_id": "CVE-2026-59265",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache OpenOffice",
      "cwe": "CWE-426",
      "title": "Apache OpenOffice, Apache OpenOffice: Opening a malicious document can lead to system takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59265"
    },
    {
      "rank": 387,
      "cve_id": "CVE-2026-103621",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-190",
      "title": "Integer overflow in Compositing in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103621"
    },
    {
      "rank": 388,
      "cve_id": "CVE-2026-103623",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in MediaStream in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103623"
    },
    {
      "rank": 389,
      "cve_id": "CVE-2026-103624",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Contextual Tasks in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103624"
    },
    {
      "rank": 390,
      "cve_id": "CVE-2026-103626",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in FileSystem in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103626"
    },
    {
      "rank": 391,
      "cve_id": "CVE-2026-103627",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Information leak in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103627"
    },
    {
      "rank": 392,
      "cve_id": "CVE-2026-103629",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-190",
      "title": "Integer overflow in Skia in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103629"
    },
    {
      "rank": 393,
      "cve_id": "CVE-2026-103630",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in FedCM in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103630"
    },
    {
      "rank": 394,
      "cve_id": "CVE-2026-103631",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-122",
      "title": "Buffer overflow in WebRTC in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103631"
    },
    {
      "rank": 395,
      "cve_id": "CVE-2026-103877",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Directory LDAP API",
      "cwe": "CWE-502",
      "title": "Apache Directory LDAP API: Unsafe loading of Java code from LDAP schema elements",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103877"
    },
    {
      "rank": 396,
      "cve_id": "CVE-2026-103878",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Directory LDAP API",
      "cwe": "CWE-345",
      "title": "Apache Directory LDAP API: Injection of plaintext responses during StartTLS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103878"
    },
    {
      "rank": 397,
      "cve_id": "CVE-2026-103880",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Directory LDAP API",
      "cwe": "CWE-405",
      "title": "Apache Directory LDAP API: Denial of service via excessive bcrypt cost factor in stored passwords",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103880"
    },
    {
      "rank": 398,
      "cve_id": "CVE-2026-103885",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Directory LDAP API",
      "cwe": null,
      "title": "Apache Directory LDAP API: Denial of service via crafted telephone number values",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103885"
    }
  ],
  "transactions": [
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-102489",
      "detail": "ADDED TO KEV — CVE-2026-102489 (Zammad GmbH Zammad). Remediation due October 5, 2026."
    },
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-102490",
      "detail": "ADDED TO KEV — CVE-2026-102490 (Zammad GmbH Zammad). Remediation due October 5, 2026."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2019-1579",
      "detail": "EXPLOIT PUBLISHED — CVE-2019-1579 (Palo Alto Networks GlobalProtect Portal/Gateway Interface). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2023-52355",
      "detail": "EXPLOIT PUBLISHED — CVE-2023-52355 (libtiff). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2023-54403",
      "detail": "EXPLOIT PUBLISHED — CVE-2023-54403 (Yonyou U8 CRM). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-102293",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-102293 (realjerrytang tacomall). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-102569",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-102569 (MacWarrior clipbucket-v5). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-102620",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-102620 (Freedesktop Poppler). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-102792",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-102792 (Ziroom ZHOME A0101). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-102804",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-102804 (Nothings stb). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-102843",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-102843 (gedelumbung HospitalManagement). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-102846",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-102846 (gedelumbung HospitalManagement). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-102906",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-102906 (0xshariq github-mcp-server). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-102910",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-102910 (SourceCodester Online Reviewer Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-102913",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-102913 (SourceCodester Car Driving School Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-103115",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-103115 (OS4ED openSIS-Classic). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-103231",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-103231 (AdithyaYelloju Restaurant-Management-System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-103241",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-103241 (vllm-project vLLM). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-3833",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-3833 (gnutls). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-4878",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-4878 (Red Hat Enterprise Linux 10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48864",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48864 (Red Hat Enterprise Linux 10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58010",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58010 (GNOME GLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58012",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58012 (GNOME GLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58013",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58013 (GNOME GLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58014",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58014 (GNOME GLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58015",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58015 (GNOME GLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58016",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58016 (GNOME GLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-64849",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-64849 (mlflow). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-66402",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-66402 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67289",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67289 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71486",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71486 (vllm-project vllm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90843",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90843 (SabyasachiRana WebMap). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-93984",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-93984 (Openpanel-dev openpanel). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-95275",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-95275 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-95363",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-95363 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-95373",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-95373 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-95374",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-95374 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-97062",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-97062 (Webkul Aureus ERP). Public exploit reference added."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2022-37009",
      "detail": "RESCORED — CVE-2022-37009 (JetBrains IntelliJ IDEA). CVSS 3.9 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-32220",
      "detail": "RESCORED — CVE-2025-32220 (Dimitri Grassi Salon booking system). CVSS 5.4 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-100255",
      "detail": "RESCORED — CVE-2026-100255 (JetBrains TeamCity). CVSS 8.1 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-100262",
      "detail": "RESCORED — CVE-2026-100262 (JetBrains YouTrack). CVSS 7.6 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-100263",
      "detail": "RESCORED — CVE-2026-100263 (JetBrains YouTrack). CVSS 4.7 → 6.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-100265",
      "detail": "RESCORED — CVE-2026-100265 (JetBrains Rider). CVSS 4.8 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-100266",
      "detail": "RESCORED — CVE-2026-100266 (JetBrains Hub). CVSS 7.7 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-100270",
      "detail": "RESCORED — CVE-2026-100270 (JetBrains YouTrack). CVSS 3.3 → 2.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-100273",
      "detail": "RESCORED — CVE-2026-100273 (JetBrains YouTrack). CVSS 8.2 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-100275",
      "detail": "RESCORED — CVE-2026-100275 (JetBrains YouTrack). CVSS 6.9 → 4.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-100276",
      "detail": "RESCORED — CVE-2026-100276 (JetBrains YouTrack). CVSS 5.9 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-100277",
      "detail": "RESCORED — CVE-2026-100277 (JetBrains YouTrack). CVSS 8.9 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-100280",
      "detail": "RESCORED — CVE-2026-100280 (JetBrains YouTrack). CVSS 3.1 → 4.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-55676",
      "detail": "RESCORED — CVE-2026-55676 (cisagov Malcolm). CVSS 8.8 → 8.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-63133",
      "detail": "RESCORED — CVE-2026-63133 (cisagov Malcolm). CVSS 6.5 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-63134",
      "detail": "RESCORED — CVE-2026-63134 (cisagov Malcolm). CVSS 5.4 → 5.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-7064",
      "detail": "RESCORED — CVE-2026-7064 (AgentDeskAI browser-tools-mcp). CVSS 6.9 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-79687",
      "detail": "RESCORED — CVE-2026-79687 (Dell PowerStore 500T). CVSS 9 → 10 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-81479",
      "detail": "RESCORED — CVE-2026-81479 (Dell OpenManage Server Administrator Managed Node (Patch) for Windows). CVSS 5.8 → 5.5 (NVD)."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-19617",
      "detail": "PATCH SHIPPED — CVE-2026-19617 (Red Hat Hardened Images). Fixed in Red Hat Hardened Images 2.03.43-1.hum1."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-55676",
      "detail": "PATCH SHIPPED — CVE-2026-55676 (cisagov Malcolm). Fixed in Malcolm 26.06.1."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-63133",
      "detail": "PATCH SHIPPED — CVE-2026-63133 (cisagov Malcolm). Fixed in Malcolm 26.07.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-63134",
      "detail": "PATCH SHIPPED — CVE-2026-63134 (cisagov Malcolm). Fixed in Malcolm 26.07.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-63177",
      "detail": "PATCH SHIPPED — CVE-2026-63177 (cisagov Malcolm). Fixed in Malcolm 26.07.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-79705",
      "detail": "PATCH SHIPPED — CVE-2026-79705 (Red Hat Hardened Images). Fixed in Red Hat Hardened Images 6.1.3-1.hum1."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-84233",
      "detail": "PATCH SHIPPED — CVE-2026-84233 (Red Hat Hardened Images). Fixed in Red Hat Hardened Images 6.1.0-1.hum1."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-88265",
      "detail": "PATCH SHIPPED — CVE-2026-88265 (Red Hat Hardened Images). Fixed in Red Hat Hardened Images 1.30-1.hum1."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-95512",
      "detail": "PATCH SHIPPED — CVE-2026-95512 (Red Hat Hardened Images). Fixed in Red Hat Hardened Images 2.14.3-2.1.hum1."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-97062",
      "detail": "PATCH SHIPPED — CVE-2026-97062 (Webkul Aureus ERP). Fixed in Aureus ERP 53ad76dd566f414f1773ec6513616fc2b9e251b5."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-100074",
      "detail": "ENRICHED — CVE-2026-100074 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-100076",
      "detail": "ENRICHED — CVE-2026-100076 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-100077",
      "detail": "ENRICHED — CVE-2026-100077 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-100078",
      "detail": "ENRICHED — CVE-2026-100078 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-100079",
      "detail": "ENRICHED — CVE-2026-100079 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-63973",
      "detail": "ENRICHED — CVE-2026-63973 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64001",
      "detail": "ENRICHED — CVE-2026-64001 (Linux). Received CVSS 7.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-98062",
      "detail": "ENRICHED — CVE-2026-98062 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-98109",
      "detail": "ENRICHED — CVE-2026-98109 (Linux). Received CVSS 4.7 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-98152",
      "detail": "ENRICHED — CVE-2026-98152 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-98160",
      "detail": "ENRICHED — CVE-2026-98160 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-98161",
      "detail": "ENRICHED — CVE-2026-98161 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-98162",
      "detail": "ENRICHED — CVE-2026-98162 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-98163",
      "detail": "ENRICHED — CVE-2026-98163 (Linux). Received CVSS 7.0 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-98164",
      "detail": "ENRICHED — CVE-2026-98164 (Linux). Received CVSS 5.5 and CPE data from NVD."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
