{
  "day": "2026-10-04",
  "boundary": "UTC calendar day",
  "published_count": 64,
  "by_severity": {
    "CRITICAL": 13,
    "HIGH": 13,
    "MEDIUM": 27,
    "LOW": 11
  },
  "kev_count": 1,
  "exploit_reference_count": 4,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-88779",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00276,
      "epss_percentile": 0.18203,
      "kev": true,
      "kev_due_at": "2026-10-07",
      "vendor": "NetScaler",
      "product": "ADC",
      "cwe": "CWE-119",
      "title": "Memory overflow vulnerability leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88779"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-105134",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01843,
      "epss_percentile": 0.78277,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ahsay",
      "product": "AhsayCBS",
      "cwe": "CWE-77",
      "title": "Ahsay AhsayCBS Replication Receiver UpdateReceivers.do os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105134"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-105135",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0077,
      "epss_percentile": 0.54065,
      "kev": false,
      "kev_due_at": null,
      "vendor": "InternLM",
      "product": "MindSearch",
      "cwe": "CWE-74",
      "title": "InternLM MindSearch Planner Agent graph.py ExecutionAction.run code injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105135"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-105144",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00539,
      "epss_percentile": 0.43382,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Drogon",
      "cwe": "CWE-22",
      "title": "Drogon Static File Router StaticFileRouter.cc route path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105144"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-105133",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00383,
      "epss_percentile": 0.30028,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ahsay",
      "product": "AhsayCBS",
      "cwe": "CWE-287",
      "title": "Ahsay AhsayCBS API ApiStructsAction.java checkSysPwd improper authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105133"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-105141",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00337,
      "epss_percentile": 0.24847,
      "kev": false,
      "kev_due_at": null,
      "vendor": "topoteretes",
      "product": "cognee",
      "cwe": "CWE-259",
      "title": "topoteretes cognee JWT Signing Key get_api_auth_backend.py get_user_id_by_email hard-coded credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105141"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-105097",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00294,
      "epss_percentile": 0.19947,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Omega Solution",
      "product": "CoinEx Crypto",
      "cwe": "CWE-285",
      "title": "Omega Solution CoinEx Crypto Customer Information API customer-currency authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105097"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-105096",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00285,
      "epss_percentile": 0.1906,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Omega Solution",
      "product": "CoinEx Crypto",
      "cwe": "CWE-285",
      "title": "Omega Solution CoinEx Crypto Customer Profile API customer authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105096"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-105098",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00279,
      "epss_percentile": 0.18508,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Omega Solution",
      "product": "CoinEx Crypto",
      "cwe": "CWE-200",
      "title": "Omega Solution CoinEx Crypto Support Ticket API customer information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105098"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-103355",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0025,
      "epss_percentile": 0.14812,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unlimited Elements",
      "product": "Unlimited Elements For Elementor (Free Widgets, Addons, Templates)",
      "cwe": "CWE-89",
      "title": "WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.20 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103355"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-105131",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00198,
      "epss_percentile": 0.0867,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mayswind",
      "product": "ezBookkeeping",
      "cwe": "CWE-863",
      "title": "mayswind ezBookkeeping 1.2.0 before 2.0.1 Privilege Escalation via Token Refresh Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105131"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-105099",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00191,
      "epss_percentile": 0.07898,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Omega Solution",
      "product": "CoinEx Crypto",
      "cwe": "CWE-79",
      "title": "Omega Solution CoinEx Crypto Ticket Attachment Upload ticket cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105099"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-17005",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.03748,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Horizontal scrolling announcements",
      "cwe": "CWE-79",
      "title": "Horizontal Scrolling Announcements <= 2.6 - Contributor+ Stored XSS via Style Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17005"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-104119",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00152,
      "epss_percentile": 0.03748,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Simple Shopping Cart",
      "cwe": "CWE-79",
      "title": "Simple Shopping Cart < 5.2.6 - Admin+ Stored XSS via PayPal API Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104119"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-97276",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.03283,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VeronaLabs",
      "product": "WP Statistics",
      "cwe": "CWE-79",
      "title": "WordPress WP Statistics plugin <= 14.16.14 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97276"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-103062",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.03283,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cozmoslabs",
      "product": "TranslatePress",
      "cwe": "CWE-79",
      "title": "WordPress TranslatePress plugin <= 3.3.6 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103062"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-103344",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.03286,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unlimited Elements",
      "product": "Unlimited Elements For Elementor (Free Widgets, Addons, Templates)",
      "cwe": "CWE-79",
      "title": "WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.20 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103344"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-103354",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.03287,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Liquid Web / StellarWP",
      "product": "Gutenberg Blocks by Kadence Blocks",
      "cwe": "CWE-79",
      "title": "WordPress Gutenberg Blocks by Kadence Blocks plugin <= 3.7.11.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103354"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-86817",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.0276,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Five Star Business Profile and Schema",
      "cwe": "CWE-200",
      "title": "Five Star Business Profile and Schema 2.3.20 - 2.3.21 - Author+ Sensitive Data Disclosure via Schema Field Default Callback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86817"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-97332",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.02565,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "User Private Files",
      "cwe": "CWE-284",
      "title": "User Private Files < 2.2.0 - Unauthenticated Private File Disclosure via .htaccess Rewrite Rule Bypass (Multisite)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97332"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-104118",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.02564,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Razorpay for WooCommerce",
      "cwe": "CWE-639",
      "title": "Razorpay for WooCommerce < 4.8.8 - Unauthenticated Order Shipping Modification via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104118"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-105137",
      "cvss_base": 1.3,
      "cvss_severity": "LOW",
      "epss_score": 0.0013,
      "epss_percentile": 0.02216,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Laradock",
      "cwe": "CWE-494",
      "title": "Laradock Build Process Dockerfile code download",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105137"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-93549",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00112,
      "epss_percentile": 0.01257,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "CoCart",
      "cwe": "CWE-352",
      "title": "CoCart 4.9.0 - 4.9.6 - Administrator Account Creation via REST API Authentication Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93549"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-105086",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-79",
      "title": "WWBN AVideo 12.4 through 29.2.0 Stored XSS via Double-Encoded Video Title",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105086"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-105089",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-79",
      "title": "WWBN AVideo through 29.2.0 Stored XSS via trailer1 in YouPHPFlix2 Templates",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105089"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-105207",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zitadel",
      "product": "zitadel",
      "cwe": "CWE-306",
      "title": "ZITADEL before 4.17.3 Account Takeover via External IdP Linking",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105207"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-105209",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zitadel",
      "product": "zitadel",
      "cwe": "CWE-862",
      "title": "ZITADEL before 3.4.15 and 4.17.1 Cross-Organization Account Takeover via Passkey Enrollment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105209"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-105215",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zitadel",
      "product": "zitadel",
      "cwe": "CWE-290",
      "title": "ZITADEL before 4.16.2 Account Pre-Hijacking via Forged External IdP Callback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105215"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-105211",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zitadel",
      "product": "zitadel",
      "cwe": "CWE-200",
      "title": "ZITADEL before 4.17.1 Authentication Bypass via Login V2 OTP returnCode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105211"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-105216",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "micro",
      "product": "go-micro",
      "cwe": "CWE-295",
      "title": "go-micro before 6.0.0 Disabled TLS Certificate Verification via tls.Config Helper",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105216"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-105218",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "go-pay",
      "product": "gopay",
      "cwe": "CWE-295",
      "title": "gopay before 1.5.119 Disabled TLS Certificate Verification in xhttp Client",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105218"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-105221",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "defunkt",
      "product": "gist",
      "cwe": "CWE-295",
      "title": "Gist RubyGem before 6.1.0 Disabled TLS Certificate Verification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105221"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-105222",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "alexpechkarev",
      "product": "google-maps",
      "cwe": "CWE-295",
      "title": "alexpechkarev/google-maps through 12.16 Disabled TLS Certificate Verification via ssl_verify_peer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105222"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-105210",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zitadel",
      "product": "zitadel",
      "cwe": "CWE-287",
      "title": "ZITADEL before 4.17.1 Unauthenticated MFA Enrollment via Login V1 Init Handlers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105210"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-105213",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zitadel",
      "product": "zitadel",
      "cwe": "CWE-287",
      "title": "ZITADEL before 4.17.1 Authentication Bypass via Login V2 for Deactivated Organizations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105213"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-105208",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zitadel",
      "product": "zitadel",
      "cwe": "CWE-649",
      "title": "ZITADEL before 4.17.3 Session Hijacking via Forgeable IdP Intent Tokens",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105208"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-105212",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zitadel",
      "product": "zitadel",
      "cwe": "CWE-287",
      "title": "ZITADEL before 3.4.14 and 4.16.2 Account Takeover via Passkey Enrollment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105212"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-105219",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mwilliamson",
      "product": "mammoth.js",
      "cwe": "CWE-1333",
      "title": "Mammoth.js 1.3.0 before 1.12.3 ReDoS via Style Map Tokeniser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105219"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-105220",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "klembot",
      "product": "twinejs",
      "cwe": "CWE-79",
      "title": "Twine 2 Desktop through 2.12.0 Arbitrary Code Execution via Imported Story Files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105220"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-97307",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "StylemixThemes",
      "product": "Cost Calculator Builder",
      "cwe": "CWE-201",
      "title": "WordPress Cost Calculator Builder plugin <= 4.0.17 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97307"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-105161",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "invariant-systems-ai",
      "product": "aiir",
      "cwe": "CWE-345",
      "title": "invariant-systems-ai aiir Policy Gate signature verification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105161"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-105163",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "crossplane",
      "product": "crossplane-runtime",
      "cwe": "CWE-362",
      "title": "crossplane crossplane-runtime ImageConfig client.go Get toctou",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105163"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-105169",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kishor-23",
      "product": "food-waste-management-system",
      "cwe": "CWE-89",
      "title": "kishor-23 food-waste-management-system Take Order delivery.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105169"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-105170",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kishor-23",
      "product": "food-waste-management-system",
      "cwe": "CWE-306",
      "title": "kishor-23 food-waste-management-system Admin Signup signup.php missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105170"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-105205",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-200",
      "title": "SiYuan before 3.8.5 Information Disclosure via /api/block/getDocInfo and getDocsInfo",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105205"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-105145",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Weaviate",
      "product": "Verba",
      "cwe": "CWE-200",
      "title": "Weaviate Verba generate_stream Endpoint util.py get_environment information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105145"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-105147",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SciPhi-AI",
      "product": "R2R",
      "cwe": "CWE-259",
      "title": "SciPhi-AI R2R JWT Secret hard-coded credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105147"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-105148",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SciPhi-AI",
      "product": "R2R",
      "cwe": "CWE-918",
      "title": "SciPhi-AI R2R Retrieval Completion API Endpoint llm.py server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105148"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-105149",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "mooSocial",
      "cwe": "CWE-74",
      "title": "mooSocial all-products sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105149"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-105158",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RainyGao",
      "product": "DocSys",
      "cwe": "CWE-74",
      "title": "RainyGao DocSys Database Management BaseController.java BaseController.createDBForMysql sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105158"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-105166",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kishor-23",
      "product": "food-waste-management-system",
      "cwe": "CWE-74",
      "title": "kishor-23 food-waste-management-system Food Donation Form fooddonateform.php insert sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105166"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-105167",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kishor-23",
      "product": "food-waste-management-system",
      "cwe": "CWE-74",
      "title": "kishor-23 food-waste-management-system donate.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105167"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-105165",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "devopspolis",
      "product": "secrets-replicator",
      "cwe": "CWE-275",
      "title": "devopspolis secrets-replicator AssumeRole handler.py process_single_secret permission assignment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105165"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-105168",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kishor-23",
      "product": "food-waste-management-system",
      "cwe": "CWE-89",
      "title": "kishor-23 food-waste-management-system Order Assignment Block admin.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105168"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-105171",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kishor-23",
      "product": "food-waste-management-system",
      "cwe": "CWE-639",
      "title": "kishor-23 food-waste-management-system Role Attribute admin.php authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105171"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-105206",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zitadel",
      "product": "zitadel",
      "cwe": "CWE-863",
      "title": "ZITADEL before 4.17.3 Cross-Organization Authentication Method Enumeration via User Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105206"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-105164",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NASA",
      "product": "cFS",
      "cwe": "CWE-119",
      "title": "NASA cFS cfe_fs_api.c CFE_FS_ParseInputFileNameEx out-of-bounds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105164"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-105224",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-79",
      "title": "YesWiki before 4.6.7 Stored XSS via Bazar valeur Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105224"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-104402",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "farvisun",
      "product": "Mindio Magic MCP",
      "cwe": "CWE-201",
      "title": "WordPress Mindio Magic MCP plugin <= 0.5.6 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104402"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-105156",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "YzmCMS",
      "cwe": "CWE-326",
      "title": "YzmCMS MD5 system.func.php password weak password hash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105156"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-105214",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zitadel",
      "product": "zitadel",
      "cwe": "CWE-918",
      "title": "Zitadel before 4.16.2 SSRF via Organization Domain HTTP Verification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105214"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-105217",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cockpit-hq",
      "product": "cockpit",
      "cwe": "CWE-295",
      "title": "Cockpit CMS 2.12.0 before 2.14.1 Disabled TLS Verification via cron.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105217"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-105157",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RainyGao",
      "product": "DocSys",
      "cwe": "CWE-22",
      "title": "RainyGao DocSys Document Controller doGetTmpFile.do DocController.doGetTmp path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105157"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-105146",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Comsenz",
      "product": "Discuz!",
      "cwe": "CWE-74",
      "title": "Comsenz Discuz! Admin Medal Moderation mod.php modmedalsubmit sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105146"
    }
  ],
  "transactions": [
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-88779",
      "detail": "ADDED TO KEV — CVE-2026-88779 (NetScaler ADC). Remediation due October 7, 2026."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-76504",
      "detail": "DUE DATE PASSED — CVE-2026-76504 (Cisco Catalyst SD-WAN Manager). CISA remediation deadline was October 3, 2026; still in catalog."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-39601",
      "detail": "PATCH SHIPPED — CVE-2026-39601 (WPdevelop Booking Calendar). Fixed in Booking Calendar 11.9."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-90947",
      "detail": "PATCH SHIPPED — CVE-2026-90947 (Red Hat Enterprise Linux 9). Fixed in Red Hat Enterprise Linux 9 2:3.0.4-4.el9_8.14."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-90948",
      "detail": "PATCH SHIPPED — CVE-2026-90948 (Red Hat Enterprise Linux 9). Fixed in Red Hat Enterprise Linux 9 2:3.0.4-4.el9_8.14."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-92248",
      "detail": "PATCH SHIPPED — CVE-2026-92248 (GNOME GIMP). Fixed in Red Hat Enterprise Linux 9 2:3.0.4-4.el9_8.14."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-97185",
      "detail": "PATCH SHIPPED — CVE-2026-97185 (Red Hat Enterprise Linux 9). Fixed in Red Hat Enterprise Linux 9 2:3.0.4-4.el9_8.14."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
