{
  "day": "2026-10-05",
  "boundary": "UTC calendar day",
  "published_count": 413,
  "by_severity": {
    "CRITICAL": 26,
    "HIGH": 105,
    "MEDIUM": 205,
    "LOW": 46
  },
  "kev_count": 0,
  "exploit_reference_count": 1,
  "awaiting_enrichment_count": 31,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-105285",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01096,
      "epss_percentile": 0.64399,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Totolink",
      "product": "A3002MU",
      "cwe": "CWE-119",
      "title": "Totolink A3002MU QoS Rule formIpQoS stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105285"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-105314",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00899,
      "epss_percentile": 0.58259,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Papermerge",
      "product": "Papermerge",
      "cwe": "CWE-24",
      "title": "Papermerge 3.5.3 allows remote code execution by a standard user via directory traversal in a /api/documents/upload call. A Python .pth file can be written to site-packages, and its code is executed upon the next start of the Python interpreter.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105314"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-105284",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00784,
      "epss_percentile": 0.54511,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Totolink",
      "product": "A3002MU",
      "cwe": "CWE-266",
      "title": "Totolink A3002MU Authentication Check boa sub_40FCFC improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105284"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-105286",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00521,
      "epss_percentile": 0.42228,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Totolink",
      "product": "A3002MU",
      "cwe": "CWE-22",
      "title": "Totolink A3002MU File Upload formUploadFile sub_44B250 path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105286"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-103507",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00513,
      "epss_percentile": 0.4167,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Perforce",
      "product": "P4 (Helix Core)",
      "cwe": "CWE-73",
      "title": "Arbitrary file-write via log configuration path in P4Search",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103507"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-19395",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00428,
      "epss_percentile": 0.34831,
      "kev": false,
      "kev_due_at": null,
      "vendor": "qt",
      "product": "Qt for MCUs",
      "cwe": "CWE-230",
      "title": "An empty <img> attribute value in styled text triggers a parser error that halts the device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19395"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-100103",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00424,
      "epss_percentile": 0.34485,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Perfoce",
      "product": "P4 (Helix Core)",
      "cwe": "CWE-1392",
      "title": "Authentication bypass via default auth token in P4Search",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100103"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-105237",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00405,
      "epss_percentile": 0.32403,
      "kev": false,
      "kev_due_at": null,
      "vendor": "linlinjava",
      "product": "litemall",
      "cwe": "CWE-307",
      "title": "linlinjava litemall Login Endpoint AdminAuthController.java excessive authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105237"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-105238",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00392,
      "epss_percentile": 0.30972,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ChatGPTNextWeb",
      "product": "NextChat",
      "cwe": "CWE-918",
      "title": "ChatGPTNextWeb NextChat Proxy Fallback proxy.ts proxyHandler server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105238"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-20586",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00382,
      "epss_percentile": 0.29837,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-787",
      "title": "In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS11383899; Issue ID: MSV-9614.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20586"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-105293",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00375,
      "epss_percentile": 0.29127,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legcord",
      "product": "Legcord",
      "cwe": "CWE-22",
      "title": "Legcord 1.1.0 through 1.3.0 Path Traversal via Theme IPC Handlers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105293"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-103512",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00374,
      "epss_percentile": 0.29047,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Perforce",
      "product": "P4 (Helix Core)",
      "cwe": "CWE-290",
      "title": "Ticket host-binding bypass via spoofed client IP in P4Search",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103512"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-100102",
      "cvss_base": 9.5,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00357,
      "epss_percentile": 0.27154,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Perforce",
      "product": "P4 (Helix Core)",
      "cwe": "CWE-489",
      "title": "RCE via exposed JDWP debug agent in P4Search",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100102"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-104810",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00352,
      "epss_percentile": 0.26564,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mitel",
      "product": "Mitel MiVoice Office 400",
      "cwe": "CWE-31",
      "title": "Mitel MiVoice Office 400 File Management File Browser path traversal vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104810"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-103510",
      "cvss_base": 9.5,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00348,
      "epss_percentile": 0.26145,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Perforce",
      "product": "P4 (Helix Core)",
      "cwe": "CWE-636",
      "title": "Authentication bypass via blank auth token in P4Search",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103510"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-105174",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00331,
      "epss_percentile": 0.23985,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Gerapy",
      "cwe": "CWE-22",
      "title": "Gerapy Project Management views.py project_create path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105174"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-103511",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00328,
      "epss_percentile": 0.23613,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Perforce",
      "product": "P4 (Helix Core)",
      "cwe": "CWE-73",
      "title": "Arbitrary file-write via extension installation in P4Search",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103511"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-105250",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00319,
      "epss_percentile": 0.22669,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "vgmstream",
      "cwe": "CWE-369",
      "title": "vgmstream Microsoft IMA Decoder ima_decoder.c decode_ms_ima divide by zero",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105250"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-105287",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00319,
      "epss_percentile": 0.22642,
      "kev": false,
      "kev_due_at": null,
      "vendor": "feelec-yishu",
      "product": "feelcrm-os",
      "cwe": "CWE-74",
      "title": "feelec-yishu feelcrm-os getMemberByGroups Endpoint AjaxRequestController.class.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105287"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-105176",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00318,
      "epss_percentile": 0.22499,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Drug Recommendation System",
      "cwe": "CWE-74",
      "title": "SourceCodester Drug Recommendation System edit_class.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105176"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-105177",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00318,
      "epss_percentile": 0.225,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Drug Recommendation System",
      "cwe": "CWE-74",
      "title": "SourceCodester Drug Recommendation System Drug Creation add_drug.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105177"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-105178",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00318,
      "epss_percentile": 0.22499,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Drug Recommendation System",
      "cwe": "CWE-74",
      "title": "SourceCodester Drug Recommendation System Symptom Creation add_symptom.php mysqli_real_escape_string sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105178"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-104806",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00313,
      "epss_percentile": 0.22001,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mitel",
      "product": "Mitel MiVoice Office 400",
      "cwe": "CWE-31",
      "title": "Mitel MiVoice Office 400 System Logs Path Traversal Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104806"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-105180",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00302,
      "epss_percentile": 0.20863,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Jeebase",
      "cwe": "CWE-913",
      "title": "Jeebase UserService info updateUser dynamically-determined object attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105180"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-13607",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00289,
      "epss_percentile": 0.19544,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "File Uploads Addon for WooCommerce",
      "cwe": "CWE-284",
      "title": "File Uploads Addon for WooCommerce <= 1.7.6 - Unauthenticated Direct File Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13607"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-104408",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00279,
      "epss_percentile": 0.18469,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Groundhogg",
      "product": "Groundhogg",
      "cwe": "CWE-89",
      "title": "WordPress Groundhogg plugin <= 4.8.3 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104408"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-103335",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00278,
      "epss_percentile": 0.18422,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Deepen Bajracharya",
      "product": "Video Conferencing with Zoom",
      "cwe": "CWE-201",
      "title": "WordPress Video Conferencing with Zoom plugin <= 4.6.10 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103335"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-105246",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.17293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Online Reviewer Management System",
      "cwe": "CWE-74",
      "title": "SourceCodester Online Reviewer Management System btn_functions.php update sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105246"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-105172",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.16497,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Online Admission System",
      "cwe": "CWE-74",
      "title": "itsourcecode Online Admission System login1.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105172"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-105182",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.16498,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Online Reviewer Management System",
      "cwe": "CWE-74",
      "title": "SourceCodester Online Reviewer Management System btn_functions.php update sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105182"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-105183",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.16495,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Online Admission System",
      "cwe": "CWE-74",
      "title": "itsourcecode Online Admission System confirm.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105183"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-105184",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.16502,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Online Admission System",
      "cwe": "CWE-74",
      "title": "itsourcecode Online Admission System creteria.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105184"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-105185",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.16503,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Online Admission System",
      "cwe": "CWE-74",
      "title": "itsourcecode Online Admission System examinee.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105185"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-105229",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.165,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kishor-23",
      "product": "food-waste-management-system",
      "cwe": "CWE-74",
      "title": "kishor-23 food-waste-management-system User Registration Endpoint signup.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105229"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-105230",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.16499,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kishor-23",
      "product": "food-waste-management-system",
      "cwe": "CWE-74",
      "title": "kishor-23 food-waste-management-system deliverymyord.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105230"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-105231",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.165,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kishor-23",
      "product": "food-waste-management-system",
      "cwe": "CWE-74",
      "title": "kishor-23 food-waste-management-system Admin Registration signup.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105231"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-105232",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.16499,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kishor-23",
      "product": "food-waste-management-system",
      "cwe": "CWE-74",
      "title": "kishor-23 food-waste-management-system Registration deliverysignup.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105232"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-105247",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.16498,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Online Reviewer Management System",
      "cwe": "CWE-74",
      "title": "SourceCodester Online Reviewer Management System btn_functions.php course sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105247"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-105253",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.16502,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Online Admission System Project",
      "cwe": "CWE-74",
      "title": "itsourcecode Online Admission System Project login1.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105253"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-104389",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0026,
      "epss_percentile": 0.1613,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sirv",
      "product": "Sirv",
      "cwe": "CWE-89",
      "title": "WordPress Sirv plugin <= 8.2.5 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104389"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-105175",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.15384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Drug Recommendation System",
      "cwe": "CWE-74",
      "title": "SourceCodester Drug Recommendation System Student Registration add_student.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105175"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-105226",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00248,
      "epss_percentile": 0.14634,
      "kev": false,
      "kev_due_at": null,
      "vendor": "osCommerce",
      "product": "osCommerce2",
      "cwe": "CWE-74",
      "title": "osCommerce osCommerce2 Newsletter Management newsletters.php include code injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105226"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-105251",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00247,
      "epss_percentile": 0.14558,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "vgmstream",
      "cwe": "CWE-119",
      "title": "vgmstream VAG File psx_decoder.c ps_find_padding out-of-bounds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105251"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-104807",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00247,
      "epss_percentile": 0.14475,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mitel",
      "product": "Mitel MiVoice Office 400",
      "cwe": "CWE-79",
      "title": "Mitel MiVoice Office 400 stored Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104807"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-104808",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00247,
      "epss_percentile": 0.14475,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mitel",
      "product": "Mitel MiVoice Office 400",
      "cwe": "CWE-79",
      "title": "Mitel MiVoice Office 400 stored Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104808"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-105248",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00242,
      "epss_percentile": 0.1395,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "vgmstream",
      "cwe": "CWE-119",
      "title": "vgmstream TXTP File txtp_parser.c txtp_parse out-of-bounds write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105248"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-105064",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00236,
      "epss_percentile": 0.13296,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unlimited Elements",
      "product": "Unlimited Elements For Elementor (Free Widgets, Addons, Templates)",
      "cwe": "CWE-470",
      "title": "WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.22 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105064"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-100727",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00233,
      "epss_percentile": 0.1293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GROWI, Inc.",
      "product": "GROWI",
      "cwe": "CWE-552",
      "title": "An improper access control vulnerability exists in GROWI, which allow an unauthenticated attacker to read files contained in non-public pages of the affected product when the file upload setting is configured as \"Local\".",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100727"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-105263",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00232,
      "epss_percentile": 0.12816,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Shaarli",
      "cwe": "CWE-918",
      "title": "Shaarli Admin Metadata Endpoint MetadataController.php MetadataController server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105263"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-20519",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00228,
      "epss_percentile": 0.12355,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-787",
      "title": "In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01778993; Issue ID: MSV-8898.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20519"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-20520",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00228,
      "epss_percentile": 0.12355,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-787",
      "title": "In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01778988; Issue ID: MSV-8897.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20520"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-20526",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00228,
      "epss_percentile": 0.12355,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-787",
      "title": "In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01898195; Issue ID: MSV-8906.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20526"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-104388",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.1231,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Blubrry Podcasting",
      "product": "PowerPress Podcasting",
      "cwe": "CWE-862",
      "title": "WordPress PowerPress Podcasting plugin <= 11.17.9 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104388"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-104397",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.12309,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jeroen Peters",
      "product": "Name Directory",
      "cwe": "CWE-862",
      "title": "WordPress Name Directory plugin <= 1.34.2 - Arbitrary Shortcode Execution vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104397"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-105233",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00227,
      "epss_percentile": 0.12233,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kishor-23",
      "product": "food-waste-management-system",
      "cwe": "CWE-384",
      "title": "kishor-23 food-waste-management-system Login Flow login.php session fixiation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105233"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-103351",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00226,
      "epss_percentile": 0.12114,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Magepeople inc.",
      "product": "Taxi Booking Manager for WooCommerce",
      "cwe": "CWE-1284",
      "title": "WordPress Taxi Booking Manager for WooCommerce plugin <= 2.1.1 - Other vulnerability Type vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103351"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-105306",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.11538,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-862",
      "title": "Keycloak-services: keycloak-services: token introspection audience bypass via dynamic client registration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105306"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2019-25777",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00218,
      "epss_percentile": 0.1114,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "YAML",
      "cwe": "CWE-502",
      "title": "YAML versions before 1.27_001 for Perl allow a loaded perl/glob document to replace any package variable, which can lead to arbitrary code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25777"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-104805",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00216,
      "epss_percentile": 0.10923,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mitel",
      "product": "Mitel MiVoice Office 400",
      "cwe": "CWE-22",
      "title": "Mitel MiVoice Office 400 Backup Restoration Arbitrary File Write Leading to Root Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104805"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-104401",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00215,
      "epss_percentile": 0.10719,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Memberful",
      "product": "Memberful - Membership Plugin",
      "cwe": "CWE-497",
      "title": "WordPress Memberful - Membership Plugin plugin <= 1.81.2 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104401"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-103078",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.10596,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ahmad",
      "product": "JS Help Desk",
      "cwe": "CWE-639",
      "title": "WordPress JS Help Desk plugin <= 4.0.0 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103078"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-20525",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00204,
      "epss_percentile": 0.0935,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-617",
      "title": "In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01870473 / MOLY00814393; Issue ID: MSV-9041.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20525"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-20527",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00204,
      "epss_percentile": 0.0935,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-129",
      "title": "In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01864925 / MOLY01210562; Issue ID: MSV-8303.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20527"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-105245",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00204,
      "epss_percentile": 0.09382,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sgl-project",
      "product": "sglang",
      "cwe": "CWE-310",
      "title": "sgl-project sglang HTTP Endpoint http_server.py server_info cleartext transmission",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105245"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-78371",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00202,
      "epss_percentile": 0.09211,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "File Uploads Addon for WooCommerce",
      "cwe": "CWE-639",
      "title": "File Uploads Addon for WooCommerce 1.7.2 - 1.7.5 - Unauthenticated Customer Uploaded File Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78371"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-105302",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.09053,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-200",
      "title": "Keycloak-services: keycloak-services: user session note mapper exposes upstream idp access tokens",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105302"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-105181",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.08952,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Online Admission System",
      "cwe": "CWE-74",
      "title": "itsourcecode Online Admission System register1.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105181"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-105186",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.08954,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Online Admission System",
      "cwe": "CWE-74",
      "title": "itsourcecode Online Admission System new.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105186"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-105187",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.08955,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Online Admission System",
      "cwe": "CWE-74",
      "title": "itsourcecode Online Admission System key.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105187"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-105254",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.08953,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Online Admission System",
      "cwe": "CWE-74",
      "title": "itsourcecode Online Admission System schoolyear.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105254"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-105223",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00199,
      "epss_percentile": 0.08761,
      "kev": false,
      "kev_due_at": null,
      "vendor": "maclof",
      "product": "kubernetes-client",
      "cwe": "CWE-295",
      "title": "maclof kubernetes-client 0.17.0 before 0.32.0 Disabled TLS Certificate Verification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105223"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-105173",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00199,
      "epss_percentile": 0.08758,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Human Resource Management",
      "cwe": "CWE-79",
      "title": "code-projects Human Resource Management Event Creation EventStore.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105173"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-105188",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00199,
      "epss_percentile": 0.08758,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Human Resource Management System",
      "cwe": "CWE-79",
      "title": "code-projects Human Resource Management System Live Event History liveEventHistory.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105188"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-105068",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.08572,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pixelite",
      "product": "Events Manager",
      "cwe": "CWE-201",
      "title": "WordPress Events Manager plugin <= 7.4.5 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105068"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-104811",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00195,
      "epss_percentile": 0.08276,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mitel",
      "product": "Mitel MiVoice Office 400",
      "cwe": "CWE-20",
      "title": "Mitel MiVoice Office 400 Music on Hold WAV File Upload Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104811"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-105294",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00189,
      "epss_percentile": 0.07685,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legcord",
      "product": "Legcord",
      "cwe": "CWE-15",
      "title": "Legcord 1.1.0 through 1.3.0 Chromium Switch Injection via settings.setConfig",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105294"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-105055",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.07525,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Mailster",
      "product": "WP Mailster",
      "cwe": "CWE-862",
      "title": "WordPress WP Mailster plugin <= 1.9.0.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105055"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-97071",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00186,
      "epss_percentile": 0.07389,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VillaTheme",
      "product": "CURCY",
      "cwe": "CWE-682",
      "title": "WordPress CURCY plugin <= 2.2.17 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97071"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-105225",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00186,
      "epss_percentile": 0.07465,
      "kev": false,
      "kev_due_at": null,
      "vendor": "osCommerce",
      "product": "osCommerce2",
      "cwe": "CWE-74",
      "title": "osCommerce osCommerce2 Payment payment.php include code injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105225"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2017-20285",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00184,
      "epss_percentile": 0.07212,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "YAML",
      "cwe": "CWE-470",
      "title": "YAML versions before 1.30 for Perl allow a loaded document to trigger the DESTROY method of arbitrary classes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2017-20285"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-103079",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.07048,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ahmad",
      "product": "JS Help Desk",
      "cwe": "CWE-639",
      "title": "WordPress JS Help Desk plugin <= 4.0.0 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103079"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-20534",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.07048,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-125",
      "title": "In Modem, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01797547; Issue ID: MSV-9155.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20534"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-20538",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.07048,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-126",
      "title": "In Modem, there is a possible out of bounds read due to a missing permission check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01774038; Issue ID: MSV-8914.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20538"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-20539",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.07047,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-126",
      "title": "In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01774038; Issue ID: MSV-8913.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20539"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-20540",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.07048,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-126",
      "title": "In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01774038; Issue ID: MSV-8912.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20540"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-20541",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.07047,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-126",
      "title": "In Modem, there is a possible out of bounds read due to a missing permission check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01774038; Issue ID: MSV-8911.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20541"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-84169",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.0702,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "UPI QR Code Payment Gateway",
      "cwe": "CWE-639",
      "title": "UPI QR Code Payment Gateway <= 1.4.3 - Unauthenticated Cross-Order Payment-Status Forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84169"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-19954",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00179,
      "epss_percentile": 0.0677,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "Net-Whois-Raw",
      "cwe": "CWE-176",
      "title": "Net::Whois::Raw versions before 2.99044 for Perl ship a pwhois command-line tool that queries WHOIS for the wrong domain for unicode domain names",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19954"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-39721",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0017,
      "epss_percentile": 0.05688,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Brainstorm Force",
      "product": "Starter Templates",
      "cwe": "CWE-862",
      "title": "WordPress Starter Templates plugin <= 4.7.7 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39721"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-20544",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00166,
      "epss_percentile": 0.053,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-787",
      "title": "In meta, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11049530 / ALPS11480843; Issue ID: MSV-7935.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20544"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-104675",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00165,
      "epss_percentile": 0.05232,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Liquid Web / StellarWP",
      "product": "Event Tickets",
      "cwe": "CWE-862",
      "title": "WordPress Event Tickets plugin <= 5.30.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104675"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-105062",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.04721,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Brandtoss",
      "product": "WP Admin Audit",
      "cwe": "CWE-862",
      "title": "WordPress WP Admin Audit plugin <= 1.2.17 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105062"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-102393",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.04627,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Brainstorm Force",
      "product": "Starter Templates",
      "cwe": "CWE-79",
      "title": "WordPress Starter Templates plugin <= 4.7.7 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102393"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-102914",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.04629,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Brainstorm Force",
      "product": "Presto Player",
      "cwe": "CWE-79",
      "title": "WordPress Presto Player plugin <= 4.5.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102914"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-103084",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.04627,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LeapWorx",
      "product": "Premium Addons for Elementor",
      "cwe": "CWE-79",
      "title": "WordPress Premium Addons for Elementor plugin <= 4.11.109 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103084"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-104396",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.04626,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jeroen Peters",
      "product": "Name Directory",
      "cwe": "CWE-79",
      "title": "WordPress Name Directory plugin <= 1.34.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104396"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-104400",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.04629,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bPlugins",
      "product": "B Blocks",
      "cwe": "CWE-79",
      "title": "WordPress B Blocks plugin <= 2.1.8 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104400"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-104404",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.04628,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Liquid Web / StellarWP",
      "product": "GiveWP",
      "cwe": "CWE-79",
      "title": "WordPress GiveWP plugin <= 4.17.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104404"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-104409",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.04626,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Chill",
      "product": "Image Photo Gallery Final Tiles Grid",
      "cwe": "CWE-79",
      "title": "WordPress Image Photo Gallery Final Tiles Grid plugin <= 3.6.13 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104409"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-104673",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.04627,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sonaar",
      "product": "MP3 Audio Player for Music, Radio & Podcast by Sonaar",
      "cwe": "CWE-79",
      "title": "WordPress MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin <= 5.14.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104673"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-105292",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.04379,
      "kev": false,
      "kev_due_at": null,
      "vendor": "chaterm",
      "product": "Chaterm",
      "cwe": "CWE-352",
      "title": "Chaterm before 0.12.1 Login CSRF via chaterm:// OAuth Callback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105292"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-105179",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00154,
      "epss_percentile": 0.03886,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Drug Recommendation System",
      "cwe": "CWE-310",
      "title": "SourceCodester Drug Recommendation System Password add_user.php missing encryption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105179"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-104386",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00146,
      "epss_percentile": 0.03286,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPFunnels Team",
      "product": "WP VR",
      "cwe": "CWE-862",
      "title": "WordPress WP VR plugin <= 9.1.3 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104386"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-104706",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00136,
      "epss_percentile": 0.02539,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mitel",
      "product": "Mitel MiVoice Office 400",
      "cwe": "CWE-31",
      "title": "Mitel MiVoice Office 400 view system files path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104706"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-20521",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00133,
      "epss_percentile": 0.02385,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-121",
      "title": "In Video HAL, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11375674; Issue ID: MSV-9571.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20521"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-20522",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00133,
      "epss_percentile": 0.02384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-787",
      "title": "In neuropilot, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11249050; Issue ID: MSV-9172.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20522"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-20523",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00133,
      "epss_percentile": 0.02385,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-787",
      "title": "In neuropilot, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11249062; Issue ID: MSV-9171.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20523"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-20524",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00133,
      "epss_percentile": 0.02384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-1285",
      "title": "In apu, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11249004; Issue ID: MSV-9170.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20524"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-105056",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.02253,
      "kev": false,
      "kev_due_at": null,
      "vendor": "impleCode",
      "product": "eCommerce Product Catalog",
      "cwe": "CWE-79",
      "title": "WordPress eCommerce Product Catalog plugin <= 3.6.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105056"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-105060",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.02252,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themepoints",
      "product": "Logo Showcase",
      "cwe": "CWE-79",
      "title": "WordPress Logo Showcase plugin <= 4.0.4 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105060"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-105069",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.02255,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nikki Blight",
      "product": "QR Redirector",
      "cwe": "CWE-79",
      "title": "WordPress QR Redirector plugin <= 2.0.5 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105069"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-105295",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.01985,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gitahead",
      "product": "GitAhead",
      "cwe": "CWE-494",
      "title": "GitAhead 2.5.0 through 2.7.1 Unverified Update Installation and TLS Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105295"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-20531",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00124,
      "epss_percentile": 0.01848,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-416",
      "title": "In apu, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11249016; Issue ID: MSV-9169.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20531"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-20543",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.0182,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-215",
      "title": "In Modem, there is a possible information disclosure due to a logic error. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01645293; Issue ID: MSV-6761.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20543"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-105301",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0012,
      "epss_percentile": 0.01618,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-918",
      "title": "Keycloak-services: keycloak-services: blind ssrf via x.509 authenticator fetching attacker-controlled crl-dp/ocsp urls",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105301"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-20528",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00119,
      "epss_percentile": 0.01586,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-787",
      "title": "In ccci, there is a possible out of bounds write and read due to a missing bounds check. This could lead to local information disclosure, memory corruption, crashes, or privilege escalation if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: ALPS11428950 (Note: For MT6880, MT6890) / ALPS10563453 (Note: For MT6980D, MT6990, MT6986, MT6986D, MT6813, MT6988) / AUTO00858766 (Note: For MT2735, MT2737); Issue ID: MSV-9893.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20528"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-19185",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00114,
      "epss_percentile": 0.01347,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-822",
      "title": "Unvalidated user-supplied buffer pointers in the I3C do_ccc system call handler allow kernel memory read/write from user mode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19185"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-20532",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01364,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-415",
      "title": "In apu, there is a possible application crash due to double free. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11249024; Issue ID: MSV-9168.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20532"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-20529",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00109,
      "epss_percentile": 0.01125,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-787",
      "title": "In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11276677; Issue ID: MSV-9217.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20529"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-20530",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00109,
      "epss_percentile": 0.01123,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-787",
      "title": "In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11292777; Issue ID: MSV-9195.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20530"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-20533",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00109,
      "epss_percentile": 0.01124,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-190",
      "title": "In display, there is a possible escalation of privilege due to an integer overflow. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11296678; Issue ID: MSV-9167.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20533"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-20536",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00109,
      "epss_percentile": 0.01125,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-416",
      "title": "In aidl, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11242428; Issue ID: MSV-9038.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20536"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-20537",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00109,
      "epss_percentile": 0.01123,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-416",
      "title": "In aidl, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11185225; Issue ID: MSV-9024.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20537"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-20542",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00109,
      "epss_percentile": 0.01124,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-416",
      "title": "In apusys, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11076799; Issue ID: MSV-8143.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20542"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-20579",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00109,
      "epss_percentile": 0.01125,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-787",
      "title": "In vdec, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11383899; Issue ID: MSV-9800.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20579"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-20587",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00109,
      "epss_percentile": 0.01125,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-843",
      "title": "In mtee, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11383899; Issue ID: MSV-9608.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20587"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-20588",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00109,
      "epss_percentile": 0.01124,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-787",
      "title": "In mtee, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11383899; Issue ID: MSV-9607.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20588"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-20589",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00109,
      "epss_percentile": 0.01124,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-787",
      "title": "In venc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11383899; Issue ID: MSV-9606.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20589"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-105249",
      "cvss_base": 2.4,
      "cvss_severity": "LOW",
      "epss_score": 0.00105,
      "epss_percentile": 0.01001,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "vgmstream",
      "cwe": "CWE-119",
      "title": "vgmstream TXTP File txtp_process.c make_group_random use after free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105249"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-19184",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00103,
      "epss_percentile": 0.00897,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-787",
      "title": "Out-of-bounds write in the NXP GAU ADC driver due to byte-versus-sample buffer size validation mismatch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19184"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-20535",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00103,
      "epss_percentile": 0.00912,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-862",
      "title": "In aidl, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11185216; Issue ID: MSV-9039.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20535"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-104407",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00097,
      "epss_percentile": 0.00694,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Blubrry Podcasting",
      "product": "PowerPress Podcasting",
      "cwe": "CWE-352",
      "title": "WordPress PowerPress Podcasting plugin <= 11.17.9 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104407"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-104809",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00087,
      "epss_percentile": 0.00326,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mitel",
      "product": "Mitel MiVoice Office 400",
      "cwe": "CWE-73",
      "title": "Mitel MiVoice Office 400 Shared Object Hijacking Leading to Arbitrary Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104809"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-105636",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "makeplane",
      "product": "plane",
      "cwe": "CWE-918",
      "title": "Plane: SSRF via HTTP redirect in webhook delivery (allow_redirects not set)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105636"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-105691",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "penpot",
      "product": "penpot",
      "cwe": "CWE-78",
      "title": "Penpot: Authenticated OS Command Injection in Penpot SVG Exporter via Legacy fill-color",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105691"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-105697",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "langflow-ai",
      "product": "langflow",
      "cwe": "CWE-78",
      "title": "Langflow: OS command injection (RCE) via arbitrary command in MCP stdio server configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105697"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-105740",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "langflow-ai",
      "product": "langflow",
      "cwe": "CWE-78",
      "title": "Langflow: Authenticated RCE via MCP Stdio transport allows any user to execute arbitrary OS commands on the server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105740"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-88395",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "GouGuOA v6.0.5 and before is vulnerable to SQL Injection in /home/message/rubbish via the keywords parameter.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88395"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-97283",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Liquid Web / StellarWP",
      "product": "Advanced Post Manager",
      "cwe": "CWE-502",
      "title": "WordPress Advanced Post Manager plugin <= 4.5.5 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97283"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-105639",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "makeplane",
      "product": "plane",
      "cwe": "CWE-200",
      "title": "Plane: Pre-auth workspace invitation hijack via email-squat and self-served invitation token leak in Plane",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105639"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-105641",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "makeplane",
      "product": "plane",
      "cwe": "CWE-798",
      "title": "Plane: Hardcoded SECRET_KEY and LIVE_SERVER_SECRET_KEY shipped in aio/cli community deployment manifests — session forgery and live-server auth bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105641"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-105637",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "makeplane",
      "product": "plane",
      "cwe": "CWE-639",
      "title": "Plane: Cross-Project Asset Hijacking via 'ProjectBulkAssetEndpoint' (sibling of CVE-2026-46558)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105637"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-105763",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "twentyhq",
      "product": "twenty",
      "cwe": "CWE-522",
      "title": "Twenty: Plaintext IMAP/SMTP/CalDAV password disclosure to any workspace member via /metadata GraphQL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105763"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-21589",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Atlassian",
      "product": "Bamboo Data Center",
      "cwe": null,
      "title": "h3. Summary This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center. Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions. Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents. In some configurations, there may be some sensitive files that make this highly severe. h3. Context This vulnerability allows an unauthenticated remote attacker to access specific files within the web application root directory in affected versions. h3. Details: * The vulnerability must be addressed for affected versions of: Bitbucket Data Center, introduced in version >= 4.6.0, fix versions: 9.4.26, 10.2.8, 10.5.1 Confluence Data Center, introduced in version >= 5.10.0, fix versions 9.2.26, 10.2.19 Crowd Data Center, introduced in version >= 2.11.0, fix versions 6.3.7, 7.0.3, 7.1.1, 7.2.4 Jira Software Data Center, introduced in version >= 7.1.0, fix versions 9.12.40, 10.3.26, 11.3.12 Jira Service Management Data Center, introduced in version >= 3.1.0, fix versions 5.12.40, 10.3.26, 11.3.12 Bamboo Data Center >= 7.0.1, fix versions 10.2.24, 12.1.12 Crucible, fix versions 4.9.15 Fisheye, fix version 4.9.15 * Exploitation requires prior knowledge of the target file's exact name and path. * The vulnerability does not include the capability to enumerate or list directory contents.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21589"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-91107",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OS4ED",
      "product": "openSIS-Classic",
      "cwe": "CWE-639",
      "title": "openSIS Classic 9.3 - Insecure Direct Object Reference (IDOR)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91107"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-102428",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ordasoft.com",
      "product": "OrdaSoft Joomla CCK",
      "cwe": "CWE-89",
      "title": "Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Joomla CCK < 8.3.16",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102428"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-103352",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP BASE",
      "product": "WP BASE Booking",
      "cwe": "CWE-89",
      "title": "WordPress WP BASE Booking plugin <= 6.4.0 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103352"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-77226",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Camunda",
      "product": "Camunda 7",
      "cwe": "CWE-863",
      "title": "Camunda 7.24.0 < 7.24.15 Incorrect Authorization via SetupResource Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77226"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-105638",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "makeplane",
      "product": "plane",
      "cwe": "CWE-307",
      "title": "Plane: Magic-code verifier endpoint has no rate limit, enabling 6-digit OTP brute force",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105638"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-105640",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "makeplane",
      "product": "plane",
      "cwe": "CWE-287",
      "title": "Plane: Account Takeover via Unverified OAuth Email Match (Gitea, self-managed GitLab)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105640"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-79820",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "HPE Integrated Lights-Out (iLO) 7",
      "cwe": "CWE-287",
      "title": "A remote user validation failure vulnerability exists in HPE Integrated Lights-Out (iLO) 7 firmware.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79820"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-45524",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-862",
      "title": "In isSystem of WifiPermissionsUtil.java, there is a possible sandbox escape due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45524"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-55280",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-457",
      "title": "In multiple locations, there is a possible out-of-bounds write due to uninitialized data. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55280"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-58835",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-122",
      "title": "In cfg2prop of btif_storage.cc, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58835"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-92931",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software",
      "product": "@progress/sitefinity-nextjs-sdk",
      "cwe": "CWE-918",
      "title": "CWE-918: Server-Side Request Forgery in the Progress Sitefinity Next.js Renderer SDK",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92931"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-97257",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PressTigers",
      "product": "Simple Event Planner",
      "cwe": "CWE-502",
      "title": "WordPress Simple Event Planner plugin <= 1.5.7 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97257"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-100511",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Vektor Inc.",
      "product": "VK Google Job Posting Manager",
      "cwe": "CWE-502",
      "title": "WordPress VK Google Job Posting Manager plugin <= 1.3.1 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100511"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-101919",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Multicluster Engine for Kubernetes",
      "cwe": "CWE-20",
      "title": "Hypershift: hypershift: unsanitized kubeconfig passthrough from tenant namespace to control plane",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101919"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-105642",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-94",
      "title": "Ghost: Remote Code Execution via Bookmark Card Images",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105642"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-102775",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "phoca.cz",
      "product": "Phoca Cart extension for Joomla",
      "cwe": "CWE-639",
      "title": "Joomla Extension - phoca.cz - Authorisation bypass through user-controlled key (IDOR) in Order View in Phoca Cart 5.0.0 - 6.1.8",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102775"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-104892",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "makeplane",
      "product": "plane",
      "cwe": "CWE-256",
      "title": "Plane: Plaintext logging of API token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104892"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-104966",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "makeplane",
      "product": "plane",
      "cwe": "CWE-639",
      "title": "Plane: Cross-Workspace IDOR in Estimate and Comment Endpoints Allows Read, Modify, and Inject Across Workspaces",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104966"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-104968",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "makeplane",
      "product": "plane",
      "cwe": "CWE-862",
      "title": "Plane: Cross-workspace member enumeration via /api/workspaces/{slug}/entity-search/",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104968"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-104976",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "makeplane",
      "product": "plane",
      "cwe": "CWE-918",
      "title": "Plane: SSRF in Gitea OAuth",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104976"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-104979",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "makeplane",
      "product": "plane",
      "cwe": "CWE-79",
      "title": "Plane: Cross-tenant stored XSS in intake enables account takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104979"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-105630",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "makeplane",
      "product": "plane",
      "cwe": "CWE-79",
      "title": "Plane: Stored XSS via SVG attachment served inline on the application origin (account takeover)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105630"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-105632",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "makeplane",
      "product": "plane",
      "cwe": "CWE-284",
      "title": "Plane: Broken Access Control - joinProject GraphQL mutation allows self-join into private (secret) projects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105632"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-63277",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Document Foundation",
      "product": "LibreOffice",
      "cwe": "CWE-829",
      "title": "RCE via calcext:data-mappings, sql provider and jdbc connector",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63277"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-103066",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP BASE",
      "product": "WP BASE Booking",
      "cwe": "CWE-89",
      "title": "WordPress WP BASE Booking plugin <= 6.4.0 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103066"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-104971",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "makeplane",
      "product": "plane",
      "cwe": "CWE-639",
      "title": "Plane: Cross-Workspace Asset Duplication IDOR + WorkspaceFileAssetEndpoint and FileAssetEndpoint Missing Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104971"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-105786",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "laurent22",
      "product": "joplin",
      "cwe": "CWE-306",
      "title": "Joplin: Unauthenticated account takeover via an attacker-chosen application-authorisation identifier",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105786"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-12171",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cookpete",
      "product": "auto-changelog",
      "cwe": "CWE-22",
      "title": "auto-changelog: code execution via untrusted in-repository configuration (handlebarsSetup/plugins), plus argument injection, path traversal, and SSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12171"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-86671",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse Che",
      "cwe": "CWE-73",
      "title": "In Eclipse Che versions 7.29.0 and later, the GET `/api/scm/resolve` and `POST /api/factory/resolver` endpoints pass an attacker-controlled URL to `URLFetcher.fetch()`, which calls `new URL(url).openConnection()` with no scheme or host allow-list and returns the response body to the caller. Any authenticated Che user can read arbitrary local files via the file:// scheme (including the pod's Kubernetes service-account token at `file:///var/run/secrets/kubernetes.io/serviceaccount/token`), reach internal HTTP services and cloud instance metadata endpoints (169.254.169.254), and have their stored SCM personal access token attached as an `Authorization` header to a host of their choosing. The same credential-forwarding behavior also fires when a victim opens a workspace from a malicious devfile whose `parent.uri` points to an attacker-controlled server, enabling exfiltration of the victim's SCM PAT without direct API access. No fix is available.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86671"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-105762",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "langgenius",
      "product": "dify",
      "cwe": "CWE-918",
      "title": "Dify: Unauthenticated Server-Side Request Forgery in /console/api/remote-files/upload endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105762"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-94201",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash",
      "cwe": "CWE-770",
      "title": "Filtering an :atom attribute with unsafe_to_atom? can exhaust the BEAM atom table in Ash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94201"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-104852",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ardatan",
      "product": "graphql-tools",
      "cwe": "CWE-1321",
      "title": "GraphQL Tools has prototype pollution in well-established utility function `mergeDeep`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104852"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-104978",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "makeplane",
      "product": "plane",
      "cwe": "CWE-863",
      "title": "Plane: Invitation Hijack in Project Join Flow via Missing Authorization and Email-Only Acceptance",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104978"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-104970",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "makeplane",
      "product": "plane",
      "cwe": "CWE-362",
      "title": "Plane: InstanceAdminSignUpEndpoint TOCTOU race allows two concurrent unauthenticated callers to both bootstrap as Plane instance admins",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104970"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-104974",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "makeplane",
      "product": "plane",
      "cwe": "CWE-284",
      "title": "Plane: Disabled User Auto-Reactivation on Login",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104974"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-105634",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "makeplane",
      "product": "plane",
      "cwe": "CWE-269",
      "title": "Plane: Privilege Escalation: Project Guest Can Demote Admin/Member Roles",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105634"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-105650",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-79",
      "title": "Ghost: Stored XSS via oEmbed Photo Responses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105650"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-105783",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "laurent22",
      "product": "joplin",
      "cwe": "CWE-346",
      "title": "Joplin Web Clipper pairing allows cross-origin theft of a permanent API token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105783"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-77805",
      "cvss_base": 7.9,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software",
      "product": "Progress® Telerik® Fiddler® Classic",
      "cwe": "CWE-347",
      "title": "Weak Executable Signature Verification Vulnerability in Progress® Telerik® Fiddler® Classic",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77805"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-49885",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-190",
      "title": "In rw_t4t_update_file of rw_t4t.cc, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49885"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-49933",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-824",
      "title": "In handle_le_monitor_device_event of msft.cc, there is a possible control-flow hijack in the privileged bluetooth process due to an uninitialized pointer dereference. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49933"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-49937",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-119",
      "title": "In multiple functions of MessageQueueBase.h, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49937"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-55266",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-400",
      "title": "In qsort of libufdt_sysdeps_vendor.c, there is a possible out-of-bounds write due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55266"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-55269",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-20",
      "title": "In FilterCapturedPacket of snoop_logger.cc, there is a possible memory safety issue due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55269"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-55270",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-441",
      "title": "In dialInternal in multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55270"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-55286",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-119",
      "title": "In stpropnci_process of stpropnci.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55286"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-58815",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-119",
      "title": "In multiple locations, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58815"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-58841",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-269",
      "title": "In multiple functions of VirtualAudioControllerTest.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58841"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-58854",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-843",
      "title": "In multiple locations, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58854"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-58859",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-248",
      "title": "In multiple places, there is a possible denial of service due to an uncaught exception. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58859"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-104977",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "makeplane",
      "product": "plane",
      "cwe": "CWE-918",
      "title": "Plane: Incomplete fix of CVE-2026-27706 — SSRF still reachable on: missing is_blocked_ip (CGNAT/multicast) + DNS-rebinding TOCTOU",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104977"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-105764",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "immich-app",
      "product": "immich",
      "cwe": "CWE-94",
      "title": "Immich: Authenticated SVG upload reaches ImageMagick coders and enables RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105764"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-97303",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apps Mav",
      "product": "Scratch & Win – Giveaways and Contests",
      "cwe": "CWE-862",
      "title": "WordPress Scratch & Win – Giveaways and Contests plugin <= 3.0.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97303"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-104973",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "makeplane",
      "product": "plane",
      "cwe": "CWE-918",
      "title": "Plane: DNS Rebinding Bypass of CVE-2026-30242 SSRF Fix in Webhook Delivery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104973"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-105628",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "makeplane",
      "product": "plane",
      "cwe": "CWE-918",
      "title": "Plane: OAuth Avatar Redirect SSRF Leads to Internal Data Exfiltration via Static Asset Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105628"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-0461",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AMD",
      "product": "Zynq™ UltraScale+ MPSoCs",
      "cwe": "CWE-787",
      "title": "Insufficient boundary validation in the USB boot mode implementation of AMD Zynq™ UltraScale+ MPSoC and RFSoC devices could allow unbounded Device Firmware Upgrade (DFU) download requests to overflow the DDR receive buffer into FSBL memory, potentially resulting in unauthorized code execution during the boot process. This issue could impact the confidentiality, integrity, or availability of affected system.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0461"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-58865",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-119",
      "title": "In multiple functions of PduParser.java, there is a possible persistent denial of service due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58865"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-93318",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moby",
      "product": "BuildKit",
      "cwe": "CWE-354",
      "title": "Cache poisoning via unvalidated image layer DiffIDs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93318"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-103334",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Etoile Web Design Incorporated",
      "product": "Five Star Restaurant Reservations",
      "cwe": "CWE-201",
      "title": "WordPress Five Star Restaurant Reservations plugin <= 2.7.24 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103334"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-104891",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "douglasborthwick-crypto",
      "product": "mppx-condition-gate",
      "cwe": "CWE-290",
      "title": "mppx-condition-gate: Free-access path grants on a self-declared wallet without proving control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104891"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-105631",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "makeplane",
      "product": "plane",
      "cwe": "CWE-639",
      "title": "Plane: asset download endpoints scope file lookups to the workspace (not the project / published entity) → cross-project & unauthenticated private-file disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105631"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-105675",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-203",
      "title": "Ghost: Invite Token Disclosure in Ghost Admin API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105675"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-105744",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "docling-project",
      "product": "docling",
      "cwe": "CWE-22",
      "title": "Docling: Arbitrary file read/write (and command execution when shell-escape is enabled) when rendering untrusted TikZ with the opt-in Tectonic engine",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105744"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-105782",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "scrapy",
      "product": "scrapy",
      "cwe": "CWE-470",
      "title": "Scrapy: Arbitrary Module Import via Referrer-Policy Header in RefererMiddleware",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105782"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-105635",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "makeplane",
      "product": "plane",
      "cwe": "CWE-200",
      "title": "Plane: Unauthenticated Project Invitation Email Disclosure Enables Unauthorized Project Join Without Token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105635"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-105643",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-79",
      "title": "Ghost: Stored XSS via Embed Card Previews",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105643"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-105649",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-79",
      "title": "Ghost: Stored XSS via SVG Uploads Bypassing Sanitization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105649"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-105651",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-79",
      "title": "Ghost: Stored XSS via Bookmark Card Images",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105651"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-105679",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-79",
      "title": "Ghost: Stored XSS via File Uploads on Local Storage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105679"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-105773",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canimaan Software",
      "product": "ClamXAV",
      "cwe": "CWE-362",
      "title": "Canimaan Software ClamXAV local privilege escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105773"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-49878",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-787",
      "title": "In wpas_handle_robust_av_scs_recv_action of robust_av.c, there is a possible out-of-bounds write due to a logic error in the code. This could lead to remote code execution with System execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49878"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-93617",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Sunshine",
      "product": "Sunshine Photo Cart",
      "cwe": "CWE-502",
      "title": "WordPress Sunshine Photo Cart plugin <= 3.7.1 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93617"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-100506",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Spell Check",
      "product": "WP Spell Check",
      "cwe": "CWE-502",
      "title": "WordPress WP Spell Check plugin <= 12.1 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100506"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-103348",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Smackcoders Inc.",
      "product": "WP Ultimate Exporter",
      "cwe": "CWE-502",
      "title": "WordPress WP Ultimate Exporter plugin <= 3.0 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103348"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-103349",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rymera Web Co",
      "product": "Product Feed PRO for WooCommerce",
      "cwe": "CWE-502",
      "title": "WordPress Product Feed PRO for WooCommerce plugin <= 13.5.7 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103349"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-104890",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kunstmaan",
      "product": "KunstmaanBundlesCMS",
      "cwe": "CWE-434",
      "title": "Kunstmaan CMS: MediaBundle extension blacklist bypass allows authenticated administrators to upload executable PHP files leading to remote code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104890"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-105677",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-22",
      "title": "Ghost: Remote Code Execution via Theme Translation Files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105677"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2025-15643",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jose Fernandez",
      "product": "Adsmonetizer",
      "cwe": "CWE-79",
      "title": "WordPress Adsmonetizer plugin <= 3.2.4 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15643"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-93316",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moby",
      "product": "BuildKit",
      "cwe": "CWE-476",
      "title": "Starting daemon with --cdi-disabled flag can lead to panic on specific builds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93316"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-97309",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webful Creations",
      "product": "RepairBuddy",
      "cwe": "CWE-862",
      "title": "WordPress RepairBuddy plugin <= 4.1226 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97309"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-100515",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VillaTheme",
      "product": "Photo Reviews for WooCommerce",
      "cwe": "CWE-79",
      "title": "WordPress Photo Reviews for WooCommerce plugin <= 1.2.30 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100515"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-102282",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cthackers",
      "product": "adm-zip",
      "cwe": "CWE-732",
      "title": "adm-zip extraction preserves SUID/SGID bits from untrusted ZIPs -> local privilege escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102282"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-104975",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "makeplane",
      "product": "plane",
      "cwe": "CWE-639",
      "title": "Plane: Cross-tenant asset authorization bypass in Plane Spaces public-board endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104975"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-105629",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "makeplane",
      "product": "plane",
      "cwe": "CWE-639",
      "title": "Plane: Cross-Tenant Destructive IDOR: Estimate Point Deletion via Unscoped Primary Key Lookup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105629"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-105633",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "makeplane",
      "product": "plane",
      "cwe": "CWE-639",
      "title": "Plane: Issue Attachment Ownership Hijacking via Missing `issue_id` Scope",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105633"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-105699",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "langflow-ai",
      "product": "langflow",
      "cwe": "CWE-639",
      "title": "Langflow: Authenticated Cross-Project File Disclosure via Unscoped MCP Resource Handlers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105699"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-105741",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "langflow-ai",
      "product": "langflow",
      "cwe": "CWE-290",
      "title": "Langflow: IP Spoofing Bypass via `X-Forwarded-For` Allowing Remote Configuration Write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105741"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-105761",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "langgenius",
      "product": "dify",
      "cwe": "CWE-639",
      "title": "Dify: IDOR in AppMCPServer PUT Endpoint Allows Modification of Other Apps' MCP Servers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105761"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-58880",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-362",
      "title": "In handle_app_val_response of btif_rc.cc, there is a possible way to achieve code execution due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58880"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-102262",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Newell Brands",
      "product": "DYMO ID",
      "cwe": "CWE-22",
      "title": "Newell Brands DYMO ID parent directory open to path traversal through improper spheres of control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102262"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-59782",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zabbix",
      "product": "Zabbix",
      "cwe": "CWE-125",
      "title": "JavaScript preprocessing memory disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59782"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-59786",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zabbix",
      "product": "Zabbix",
      "cwe": "CWE-940",
      "title": "Active agent heartbeat missing TLS check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59786"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-93321",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moby",
      "product": "BuildKit",
      "cwe": "CWE-129",
      "title": "Malformed LLB file operation can crash buildkitd",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93321"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-93322",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moby",
      "product": "BuildKit",
      "cwe": "CWE-129",
      "title": "Malformed MergeOp can crash the BuildKit daemon",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93322"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-97070",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CozyThemes",
      "product": "Cozy Blocks",
      "cwe": "CWE-639",
      "title": "WordPress Cozy Blocks plugin <= 2.2.23 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97070"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-97305",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themeisle",
      "product": "AI Chatbot for WordPress – Hyve Lite",
      "cwe": "CWE-639",
      "title": "WordPress AI Chatbot for WordPress – Hyve Lite plugin <= 2.0.2 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97305"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-102779",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomlafry.com",
      "product": "TF Content for Joomla",
      "cwe": "CWE-862",
      "title": "Joomla Extension - joomlafry.com - Unauthenticated forced execution of published automation tasks in TF Content 2.9.0 - 2.9.4",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102779"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-102780",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomlafry.com",
      "product": "TF Content for Joomla",
      "cwe": "CWE-862",
      "title": "Joomla Extension - joomlafry.com - Unauthenticated cross-record publication and mass assignment in TF Content 2.9.0 - 2.9.4",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102780"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-103433",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Docker",
      "product": "Docker Buildx",
      "cwe": "CWE-862",
      "title": "Bake filesystem entitlement consent is skipped for certain secret and oci-layout definitions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103433"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-105471",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "girishsaraf",
      "product": "Online-Appointment-Booking-System",
      "cwe": "CWE-89",
      "title": "girishsaraf Online-Appointment-Booking-System Registration signup.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105471"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-105751",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "docling-project",
      "product": "docling",
      "cwe": "CWE-22",
      "title": "Docling: Arbitrary local file read via draw:image xlink:href in the OpenDocument backend",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105751"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-63266",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Document Foundation",
      "product": "LibreOffice",
      "cwe": "CWE-22",
      "title": "Arbitrary file write via calcext:data-mappings, sql provider and Firebird backup functionality",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63266"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-84900",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HP Inc",
      "product": "ThinPro 8.1",
      "cwe": "CWE-354",
      "title": "HP ThinPro 8.1 SP10 and ThinPro 9 SP3 Security Updates",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84900"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-93323",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moby",
      "product": "BuildKit",
      "cwe": "CWE-789",
      "title": "Oversized Dockerfile or .dockerignore can exhaust buildkitd memory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93323"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-104964",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "makeplane",
      "product": "plane",
      "cwe": "CWE-639",
      "title": "Plane: Cross-Workspace Project Modification via Unscoped Project Lookup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104964"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-105644",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-79",
      "title": "Ghost: Stored XSS via SVG Files in Content Imports",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105644"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-63267",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Document Foundation",
      "product": "LibreOffice",
      "cwe": "CWE-200",
      "title": "LFI and GET SSRF via calcext:data-mappings and csv provider",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63267"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-63268",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Document Foundation",
      "product": "LibreOffice",
      "cwe": "CWE-200",
      "title": "LFI via calcext:data-mappings, sql provider and sdbc:flat:file:// db href",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63268"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-63269",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Document Foundation",
      "product": "LibreOffice",
      "cwe": "CWE-200",
      "title": "LFI and GET SSRF via GStreamer and HLS playlists",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63269"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-63270",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Document Foundation",
      "product": "LibreOffice",
      "cwe": "CWE-200",
      "title": "Environment/ini-file leaks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63270"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-105688",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "penpot",
      "product": "penpot",
      "cwe": "CWE-269",
      "title": "Penpot: Team admin can escalate to owner via team invitation (missing owner-role guard on the invitation path)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105688"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-105745",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "docling-project",
      "product": "docling",
      "cwe": "CWE-696",
      "title": "Docling: Plugin entry points are imported before the allow_external_plugins check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105745"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-77804",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software",
      "product": "Progress® Telerik® Fiddler® Classic",
      "cwe": "CWE-367",
      "title": "Time-of-check Time-of-use (TOCTOU) Race Condition in Root Certificate Installation in Progress® Telerik® Fiddler® Classic",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77804"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-42700",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GhozyLab",
      "product": "Image Slider Widget",
      "cwe": "CWE-79",
      "title": "WordPress Image Slider Widget plugin <= 1.1.130 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42700"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-55265",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-119",
      "title": "In multiple functions of PduParser.java, there is a possible out of bounds read due to a missing bounds check. This could lead to a remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55265"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-71299",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Multicluster Engine for Kubernetes",
      "cwe": "CWE-306",
      "title": "Maestro: maestro: rest api write endpoints registered without authentication middleware",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71299"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-78411",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rapid7",
      "product": "Velociraptor",
      "cwe": "CWE-863",
      "title": "Velociraptor Server Metadata update with Insufficient Permission Check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78411"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-89039",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Grafana",
      "product": "mcp-k6",
      "cwe": "CWE-22",
      "title": "Arbitrary file read via the convert_playwright_script prompt in mcp-k6",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89039"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-97304",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arraytics",
      "product": "Timetics",
      "cwe": "CWE-862",
      "title": "WordPress Timetics plugin <= 1.0.63 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97304"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-100509",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webful Creations",
      "product": "RepairBuddy",
      "cwe": "CWE-79",
      "title": "WordPress RepairBuddy plugin <= 4.1225 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100509"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-102383",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VillaTheme",
      "product": "Lookzy",
      "cwe": "CWE-862",
      "title": "WordPress Lookzy plugin <= 1.1.14 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102383"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-103085",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP User Manager",
      "product": "WP User Manager",
      "cwe": "CWE-284",
      "title": "WordPress WP User Manager plugin <= 2.9.20 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103085"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-103086",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Stiofan",
      "product": "UsersWP",
      "cwe": "CWE-862",
      "title": "WordPress UsersWP plugin <= 1.2.74 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103086"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-103337",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kirillbdev",
      "product": "WC Ukraine Shipping",
      "cwe": "CWE-862",
      "title": "WordPress WC Ukraine Shipping plugin <= 1.23.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103337"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-104960",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "makeplane",
      "product": "plane",
      "cwe": "CWE-639",
      "title": "Plane: Authorization bypass in workspace-scoped asset download endpoint exposes secret project file assets to non-project workspace users",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104960"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-104962",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "makeplane",
      "product": "plane",
      "cwe": "CWE-862",
      "title": "Plane: Cross-project member roster IDOR in ProjectMemberListCreateAPIEndpoint (missing project scope on reads)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104962"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-104969",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "makeplane",
      "product": "plane",
      "cwe": "CWE-639",
      "title": "Plane: Cross-Tenant Cycle Issue Hijack via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104969"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-105680",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-862",
      "title": "Ghost: Authorization Issue Allowed Author Role to Delete any Post",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105680"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-105681",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-943",
      "title": "Ghost: Authorization Bypass in Comments Feature",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105681"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-105696",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "penpot",
      "product": "penpot",
      "cwe": "CWE-862",
      "title": "Penpot: Share-link page-scope escalation: a share-link holder reads pages outside the link's authorized scope via the get-page RPC command",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105696"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-105749",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "docling-project",
      "product": "docling",
      "cwe": "CWE-400",
      "title": "Docling: Unbounded table rowspan/colspan in HTML, JATS, ODS and BoxNote backends causes CPU/memory exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105749"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-105753",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vllm",
      "cwe": "CWE-617",
      "title": "vLLM: Mirrored multimodal IPC caches desync after a rejected request — a later request reusing the same media hash trips a receiver assertion in the engine core",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105753"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-105754",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vllm",
      "cwe": "CWE-20",
      "title": "vLLM: Scale-out disaggregated multimodal transport trusts caller-supplied features",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105754"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-105756",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vllm",
      "cwe": "CWE-20",
      "title": "vLLM: Loose `cache_salt` validation lets a single request kill EngineCore on LMCache-MP deployments — uncaught downstream `ValueError` denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105756"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-105757",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vllm",
      "cwe": "CWE-20",
      "title": "vLLM: Structured-output request errors escape the request boundary and terminate the shared EngineCore — engine-fatal denial of service (3 sites)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105757"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-71298",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Multicluster Engine for Kubernetes",
      "cwe": "CWE-89",
      "title": "Maestro: sql identifier injection via properties.* search filter and orderby field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71298"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-77802",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software",
      "product": "Progress® Telerik® Fiddler® Classic",
      "cwe": "CWE-444",
      "title": "HTTP Request Smuggling Vulnerability in Progress® Telerik® Fiddler® Classic",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77802"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-102777",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "svenbluege.de",
      "product": "Event Gallery for Joomla",
      "cwe": "CWE-918",
      "title": "Joomla Extension - svenbluege.de - Server-side request forgery in the Google Photos picker in Event Gallery extension < 6.6.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102777"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-105768",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "chainguard-dev",
      "product": "apko",
      "cwe": "CWE-197",
      "title": "apko /etc/passwd and /etc/group UID/GID truncation writes package-supplied entries as root",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105768"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-104905",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NeoRazorX",
      "product": "facturascripts",
      "cwe": "CWE-502",
      "title": "FacturaScripts < 2026.7 PHP Object Injection via WidgetSelect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104905"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-93320",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moby",
      "product": "BuildKit",
      "cwe": "CWE-441",
      "title": "BuildKit improperly handles special files in build snapshots",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93320"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-93326",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moby",
      "product": "BuildKit",
      "cwe": "CWE-180",
      "title": "Crafted Git build source can bypass certain policy validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93326"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-105689",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "penpot",
      "product": "penpot",
      "cwe": "CWE-918",
      "title": "Penpot: SSRF guard bypass via IPv6 transition addresses (NAT64/6to4/Teredo) in webhook delivery and media download",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105689"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-93317",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moby",
      "product": "BuildKit",
      "cwe": "CWE-354",
      "title": "Container blob cache can accept unverified content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93317"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-105690",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "penpot",
      "product": "penpot",
      "cwe": "CWE-613",
      "title": "Penpot: Server-side session not invalidated on logout; stale auth-token cookie remains valid for full profile access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105690"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-105695",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "penpot",
      "product": "penpot",
      "cwe": "CWE-862",
      "title": "Penpot: Missing authorization in chunked-upload assembly lets another authenticated user consume a victim's upload session",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105695"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-105750",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "docling-project",
      "product": "docling",
      "cwe": "CWE-552",
      "title": "Docling: `enable_local_fetch` is not enforced in HTML browser-rendering mode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105750"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-105759",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vllm",
      "cwe": "CWE-400",
      "title": "vLLM: Unbounded Prometheus label cardinality from attacker-controlled HTTP method tokens in the vLLM Rust frontend metrics middleware (unauthenticated denial of service)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105759"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-93315",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moby",
      "product": "BuildKit",
      "cwe": "CWE-367",
      "title": "BuildKit proxy CA cleanup can be disrupted by build steps",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93315"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-59788",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zabbix",
      "product": "Zabbix",
      "cwe": "CWE-79",
      "title": "Stored XSS vulnerability in OAuth configuration form",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59788"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-93319",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moby",
      "product": "BuildKit",
      "cwe": "CWE-567",
      "title": "A malicious frontend can cause a daemon panic",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93319"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-28667",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-119",
      "title": "In multiple functions of rw_t5t.cc, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28667"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-58834",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-20",
      "title": "In setPermissionGrantState of DevicePolicyManagerService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58834"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-78413",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rapid7",
      "product": "Velociraptor",
      "cwe": "CWE-276",
      "title": "Velociraptor privilege escalation via SysmonLogForward client monitoring artifact",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78413"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-104030",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-125",
      "title": "Sssd: sssd: denial of service via out-of-bounds read during passkey parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104030"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-105290",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "feelec-yishu",
      "product": "feelcrm-os",
      "cwe": "CWE-918",
      "title": "feelec-yishu feelcrm-os getCurlData Endpoint GoogleController.class.php server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105290"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-105307",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Casdoor",
      "cwe": "CWE-287",
      "title": "Casdoor API Endpoint authz_filter.go ApiFilter missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105307"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-105382",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "onetwothreeneth",
      "product": "HospitalManagementSystem",
      "cwe": "CWE-266",
      "title": "onetwothreeneth HospitalManagementSystem Account Administration controller.php update_subaccount improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105382"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-105383",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "onetwothreeneth",
      "product": "HospitalManagementSystem",
      "cwe": "CWE-74",
      "title": "onetwothreeneth HospitalManagementSystem controller.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105383"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-105384",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "UNION",
      "product": "HospitalManagementSystem",
      "cwe": "CWE-74",
      "title": "UNION HospitalManagementSystem patient_info.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105384"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-105385",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "onetwothreeneth",
      "product": "HospitalManagementSystem",
      "cwe": "CWE-74",
      "title": "onetwothreeneth HospitalManagementSystem transaction_details.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105385"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-105386",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "onetwothreeneth",
      "product": "HospitalManagementSystem",
      "cwe": "CWE-74",
      "title": "onetwothreeneth HospitalManagementSystem print.php get sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105386"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-105387",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "girishsaraf",
      "product": "Online-Appointment-Booking-System",
      "cwe": "CWE-74",
      "title": "girishsaraf Online-Appointment-Booking-System Patient Login cover.php mysqli_query sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105387"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-105392",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lybbn",
      "product": "Django-Vue-Lyadmin",
      "cwe": "CWE-320",
      "title": "Lybbn Django-Vue-Lyadmin JWT Signing settings.py hard-coded key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105392"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-105447",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Quay 3",
      "cwe": "CWE-863",
      "title": "Quay: quay: global read-only superuser can access build trigger write credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105447"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-105468",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "girishsaraf",
      "product": "Online-Appointment-Booking-System",
      "cwe": "CWE-74",
      "title": "girishsaraf Online-Appointment-Booking-System Login mlogin.php mysqli_query sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105468"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-105469",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "girishsaraf",
      "product": "Online-Appointment-Booking-System",
      "cwe": "CWE-74",
      "title": "girishsaraf Online-Appointment-Booking-System AJAX Endpoint get_town.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105469"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-105470",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "girishsaraf",
      "product": "Online-Appointment-Booking-System",
      "cwe": "CWE-74",
      "title": "girishsaraf Online-Appointment-Booking-System Doctor Search Endpoint locateus.php mysqli_query sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105470"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-0482",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AMD",
      "product": "Alveo™ Accelerator Cards",
      "cwe": "CWE-787",
      "title": "In AMD Versal™ Adaptive SoC devices, insufficient boundary checks in USB boot mode—when enabled through board modifications—could allow crafted images to trigger a buffer overflow and overwrite an active function pointer, which may result in arbitrary code execution during boot process. This condition could lead to potential impacts on confidentiality, integrity, and availability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0482"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-71297",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Multicluster Engine for Kubernetes",
      "cwe": "CWE-306",
      "title": "Maestro: maestro: grpc broker has no auth interceptor and client mtls is optional",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71297"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-102295",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Quay 3",
      "cwe": "CWE-79",
      "title": "Quay: quay: dom-based cross-site scripting via oauth local callback format=json parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102295"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-104893",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "makeplane",
      "product": "plane",
      "cwe": "CWE-770",
      "title": "Plane: Improper validation allows arbitrary modification of API token rate limits",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104893"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-104955",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "makeplane",
      "product": "plane",
      "cwe": "CWE-269",
      "title": "Plane: Project Member can escalate Project Guest to Member via PATCH /project-members/{pk} (BAC / Privilege Escalation)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104955"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-104961",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "makeplane",
      "product": "plane",
      "cwe": "CWE-863",
      "title": "Plane: WorkspaceOwnerPermission missing is_active check allows deactivated users to retain owner access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104961"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-104965",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "makeplane",
      "product": "plane",
      "cwe": "CWE-639",
      "title": "Plane: Cross-Tenant Issue Relation Creation via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104965"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-104967",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "makeplane",
      "product": "plane",
      "cwe": "CWE-639",
      "title": "Plane: Cross-workspace association destruction and issue mutation/read via unscoped queries in BulkDeleteIssuesEndpoint and SubIssuesEndpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104967"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-105692",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "penpot",
      "product": "penpot",
      "cwe": "CWE-284",
      "title": "Penpot: IDOR in Share-Link Deletion Allows Any File Editor to Delete Share-Links They Did Not Create",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105692"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-105694",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "penpot",
      "product": "penpot",
      "cwe": "CWE-79",
      "title": "Penpot: Stored XSS via Unsanitised SVG Uploads",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105694"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-105698",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "langflow-ai",
      "product": "langflow",
      "cwe": "CWE-639",
      "title": "Langflow: Cross-user flow access and vertex execution via deprecated /api/v1/build/{flow_id}/vertices endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105698"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-59787",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zabbix",
      "product": "Zabbix",
      "cwe": "CWE-143",
      "title": "SNMP trap injection in zabbix_trap_receiver.pl",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59787"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-94669",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP ManageNinja LLC",
      "product": "Fluent Forms Pro Add On Pack",
      "cwe": "CWE-862",
      "title": "WordPress Fluent Forms Pro Add On Pack plugin <= 6.2.13 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94669"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-97275",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VillaTheme",
      "product": "BuildKit – Product Builder for WooCommerce – Custom PC Builder",
      "cwe": "CWE-1284",
      "title": "WordPress BuildKit – Product Builder for WooCommerce – Custom PC Builder plugin <= 1.0.28 - Bypass Vulnerability vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97275"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-102426",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomshaper.com",
      "product": "SP Page Builder (Pro) extension for Joomla",
      "cwe": "CWE-79",
      "title": "Joomla Extension - joomshaper.com - Reflected XSS in the Dynamic Content Filter addon in SP Page Builder Pro 3.0.0 - 5.6.1p2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102426"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-102778",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "svenbluege.de",
      "product": "Event Gallery for Joomla",
      "cwe": "CWE-352",
      "title": "Joomla Extension - svenbluege.de - Cross-site scripting and open redirect on the share mini page in Event Gallery extension < 6.6.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102778"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-103684",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arraytics",
      "product": "WP Event Solution",
      "cwe": "CWE-862",
      "title": "WordPress WP Event Solution plugin <= 4.1.25 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103684"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-104956",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "makeplane",
      "product": "plane",
      "cwe": "CWE-943",
      "title": "Plane: Unauthenticated ORM field-name injection via `group_by`/`sub_group_by` on public deploy boards (DoS + blind oracle)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104956"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-105073",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arraytics",
      "product": "WP Event Solution",
      "cwe": "CWE-497",
      "title": "WordPress WP Event Solution plugin <= 4.1.25 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105073"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-105396",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "heymrun",
      "product": "heym",
      "cwe": "CWE-346",
      "title": "Heym before v0.0.112 HITL Review Token Leak via Spoofable Origin Header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105396"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-105421",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kit",
      "product": "Kit (formerly ConvertKit) for WooCommerce",
      "cwe": "CWE-862",
      "title": "WordPress Kit (formerly ConvertKit) for WooCommerce plugin <= 2.2.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105421"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-105686",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "penpot",
      "product": "penpot",
      "cwe": "CWE-770",
      "title": "Penpot: Repeated chunk index causes temporary-storage amplification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105686"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-105693",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "penpot",
      "product": "penpot",
      "cwe": "CWE-862",
      "title": "Penpot: Anonymous share-link token disclosure & page-scope bypass via get-view-only-bundle",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105693"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-105758",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vllm",
      "cwe": "CWE-770",
      "title": "vLLM: Qwen2-VL / Qwen3-VL video samplers bound on request-controlled max_frames, which the num_frames ceiling does not reach",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105758"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-105760",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vllm",
      "cwe": "CWE-400",
      "title": "vLLM: GLMGA video sampling permits request-driven CPU and memory exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105760"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-59785",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zabbix",
      "product": "Zabbix",
      "cwe": "CWE-204",
      "title": "Hidden host credentials inferable via multiselect.get filtering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59785"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-101893",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Newell Brands",
      "product": "DYMO ID",
      "cwe": "CWE-611",
      "title": "Newell Brands DYMO ID document parsing failing file type extension authentication check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101893"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-102776",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "svenbluege.de",
      "product": "Event Gallery for Joomla",
      "cwe": "CWE-352",
      "title": "Joomla Extension - svenbluege.de - Cross-site request forgery of list tasks of the backend in Event Gallery extension < 6.6.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102776"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-105397",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThimPress",
      "product": "LearnPress",
      "cwe": "CWE-79",
      "title": "LearnPress WordPress Plugin through 4.4.9.1 Stored XSS via Quiz Question Hint and Explanation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105397"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-78412",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rapid7",
      "product": "Velociraptor",
      "cwe": "CWE-639",
      "title": "WatchEvent API streams another organization's live events",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78412"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-105645",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-1333",
      "title": "Ghost: Regular Expression Denial of Service in External Media Inliner",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105645"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-105646",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-1333",
      "title": "Ghost: Regular Expression Denial of Service in Content Import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105646"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-105676",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-22",
      "title": "Ghost: Path Traversal via Locale Setting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105676"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-105687",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "penpot",
      "product": "penpot",
      "cwe": "CWE-269",
      "title": "Penpot: A team admin (non-owner) can remove the team owner via ::delete-team-member — missing owner-protection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105687"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2026-105785",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "laurent22",
      "product": "joplin",
      "cwe": "CWE-620",
      "title": "Joplin Server password reset accepts tokens issued for unrelated purposes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105785"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-105784",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "laurent22",
      "product": "joplin",
      "cwe": "CWE-79",
      "title": "Joplin whiteboard card rendering allows CSS injection into application chrome",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105784"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-39763",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Deepak Anand",
      "product": "WP Dummy Content Generator",
      "cwe": "CWE-862",
      "title": "WordPress WP Dummy Content Generator plugin <= 4.0.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39763"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-39783",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP SYNTEX",
      "product": "Polylang",
      "cwe": "CWE-862",
      "title": "WordPress Polylang plugin <= 3.8.7 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39783"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-104894",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "makeplane",
      "product": "plane",
      "cwe": "CWE-639",
      "title": "Plane: Cross-Tenant Module Issue Linking via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104894"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-104963",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "makeplane",
      "product": "plane",
      "cwe": "CWE-200",
      "title": "Plane: Workspace cycle and module endpoints missing project-membership filter expose private project metadata to any workspace member",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104963"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2026-105678",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-269",
      "title": "Ghost: Editors Could Promote Staff Users to Their Own Role",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105678"
    },
    {
      "rank": 354,
      "cve_id": "CVE-2026-105684",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "penpot",
      "product": "penpot",
      "cwe": "CWE-200",
      "title": "Penpot: Share-link page-scope escape — comment RPCs leak comment content, author identity, and all page-ids for pages outside the share scope",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105684"
    },
    {
      "rank": 355,
      "cve_id": "CVE-2026-105747",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "docling-project",
      "product": "docling",
      "cwe": "CWE-409",
      "title": "Docling: METS-GBS archive member limit enforced after full member enumeration (memory exhaustion during format detection)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105747"
    },
    {
      "rank": 356,
      "cve_id": "CVE-2026-105748",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "docling-project",
      "product": "docling",
      "cwe": "CWE-73",
      "title": "Docling: Crafted DoclingDocument JSON embeds local image files into converted output",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105748"
    },
    {
      "rank": 357,
      "cve_id": "CVE-2026-102576",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Quay 3",
      "cwe": "CWE-79",
      "title": "Quay: quay: dom-based cross-site scripting via unvalidated redirect_url on signin page",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102576"
    },
    {
      "rank": 358,
      "cve_id": "CVE-2026-105755",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vllm",
      "cwe": "CWE-639",
      "title": "vLLM: Flash late-interaction scoring caches query embeddings under a caller-controlled request id — cross-request integrity break and induced errors on `/score` and `/rerank`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105755"
    },
    {
      "rank": 359,
      "cve_id": "CVE-2026-105647",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-367",
      "title": "Ghost: Server-Side Request Forgery in Bookmark Fetching",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105647"
    },
    {
      "rank": 360,
      "cve_id": "CVE-2026-105648",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-184",
      "title": "Ghost: Private IP Filtering Bypass via IPv6 Transition Addresses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105648"
    },
    {
      "rank": 361,
      "cve_id": "CVE-2026-105743",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "docling-project",
      "product": "docling",
      "cwe": "CWE-367",
      "title": "Docling: SSRF guard bypass in remote resource fetching (DNS rebinding / multi-record resolution; no IP validation in HTML render mode)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105743"
    },
    {
      "rank": 362,
      "cve_id": "CVE-2026-105683",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-35",
      "title": "Ghost: Path Traversal Vulnerability in Ghost ImageSize Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105683"
    },
    {
      "rank": 363,
      "cve_id": "CVE-2026-105742",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "docling-project",
      "product": "docling",
      "cwe": "CWE-201",
      "title": "Docling: Configured HTTP headers sent to every remote image host named by a document",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105742"
    },
    {
      "rank": 364,
      "cve_id": "CVE-2026-77803",
      "cvss_base": 3.6,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software",
      "product": "Progress® Telerik® Fiddler® Classic",
      "cwe": "CWE-444",
      "title": "Front-end Desynchronization Vulnerability in Progress® Telerik® Fiddler® Classic",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77803"
    },
    {
      "rank": 365,
      "cve_id": "CVE-2026-105712",
      "cvss_base": 3.6,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GnuPG",
      "product": "GnuPG",
      "cwe": "CWE-61",
      "title": "gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105712"
    },
    {
      "rank": 366,
      "cve_id": "CVE-2026-58856",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-119",
      "title": "In returnOutputBufferLocked of DeprecatedCamera3StreamSplitter.cpp, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58856"
    },
    {
      "rank": 367,
      "cve_id": "CVE-2026-104029",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-125",
      "title": "Sssd: sssd: denial of service via out-of-bounds read in autofs responder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104029"
    },
    {
      "rank": 368,
      "cve_id": "CVE-2026-105652",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-203",
      "title": "Ghost: Password Hash Ordering Disclosure in Ghost Admin API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105652"
    },
    {
      "rank": 369,
      "cve_id": "CVE-2026-105752",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vllm",
      "cwe": "CWE-200",
      "title": "vLLM: Harmony tool continuations drop `cache_salt` — restoring a cross-tenant prefix-cache membership oracle",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105752"
    },
    {
      "rank": 370,
      "cve_id": "CVE-2026-105682",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-918",
      "title": "Ghost: Server-Side Request Forgery in Webhook Trigger",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105682"
    },
    {
      "rank": 371,
      "cve_id": "CVE-2026-105326",
      "cvss_base": 2.5,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-88",
      "title": "Cups: cups: argument injection in mailto notifier via notify-recipient-uri",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105326"
    },
    {
      "rank": 372,
      "cve_id": "CVE-2026-59783",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zabbix",
      "product": "Zabbix",
      "cwe": "CWE-787",
      "title": "Server DoS via binary items",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59783"
    },
    {
      "rank": 373,
      "cve_id": "CVE-2026-103546",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB, Inc.",
      "product": "Mongodb Controllers for Kubernetes",
      "cwe": "CWE-918",
      "title": "Improper validation of Ops Manager configuration in MongoDB Kubernetes Operator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103546"
    },
    {
      "rank": 374,
      "cve_id": "CVE-2026-105766",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Chainguard",
      "product": "Chainguard Academy (edu)",
      "cwe": "CWE-319",
      "title": "Chainguard Academy (edu) Nginx directory redirect downgrades HTTPS requests to HTTP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105766"
    },
    {
      "rank": 375,
      "cve_id": "CVE-2026-105746",
      "cvss_base": 2.2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "docling-project",
      "product": "docling",
      "cwe": "CWE-668",
      "title": "Docling: KServe v2 OCR engine does not enforce enable_remote_services",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105746"
    },
    {
      "rank": 376,
      "cve_id": "CVE-2026-105288",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "feelec-yishu",
      "product": "feelcrm-os",
      "cwe": "CWE-79",
      "title": "feelec-yishu feelcrm-os Crm Endpoint functions.php index cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105288"
    },
    {
      "rank": 377,
      "cve_id": "CVE-2026-105291",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "feelec-yishu",
      "product": "feelcrm-os",
      "cwe": "CWE-79",
      "title": "feelec-yishu feelcrm-os Department Search Endpoint GroupController.class.php index cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105291"
    },
    {
      "rank": 378,
      "cve_id": "CVE-2026-105329",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "TallCMS",
      "cwe": "CWE-74",
      "title": "TallCMS PluginManager ThemeManager.php code injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105329"
    },
    {
      "rank": 379,
      "cve_id": "CVE-2026-105388",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "feelec-yishu",
      "product": "feelcrm-os",
      "cwe": "CWE-74",
      "title": "feelec-yishu feelcrm-os Member Endpoint MemberController.class.php index sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105388"
    },
    {
      "rank": 380,
      "cve_id": "CVE-2026-105389",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "feelec-yishu",
      "product": "feelcrm-os",
      "cwe": "CWE-284",
      "title": "feelec-yishu feelcrm-os UploadTicketFile Endpoint UploadController.class.php unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105389"
    },
    {
      "rank": 381,
      "cve_id": "CVE-2026-105438",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "O2OA",
      "cwe": "CWE-918",
      "title": "O2OA General url ActionUploadExcelWithUrl server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105438"
    },
    {
      "rank": 382,
      "cve_id": "CVE-2026-105444",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dotnet",
      "product": "eShop",
      "cwe": "CWE-99",
      "title": "dotnet eShop Ordering API OrdersApi.cs GetOrderAsync resource injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105444"
    },
    {
      "rank": 383,
      "cve_id": "CVE-2026-105767",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Chainguard",
      "product": "Chainguard Academy (edu)",
      "cwe": "CWE-78",
      "title": "Chainguard Academy (edu) integrate-platform-docs composite action interpolates inputs into shell commands",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105767"
    },
    {
      "rank": 384,
      "cve_id": "CVE-2026-105289",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "feelec-yishu",
      "product": "feelcrm-os",
      "cwe": "CWE-79",
      "title": "feelec-yishu feelcrm-os Create Customer Endpoint CrmDefineFormModel.class.php htmlspecialchars_decode cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105289"
    },
    {
      "rank": 385,
      "cve_id": "CVE-2026-105315",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "django-haystack",
      "cwe": "CWE-94",
      "title": "django-haystack more_like_this Template Tag elasticsearch_backend.py _to_python eval injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105315"
    },
    {
      "rank": 386,
      "cve_id": "CVE-2026-28625",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28625"
    },
    {
      "rank": 387,
      "cve_id": "CVE-2026-28640",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In checkCallerIsCertInstallerOrSelfInProfile of CredentialStorageActivity.java, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28640"
    },
    {
      "rank": 388,
      "cve_id": "CVE-2026-28641",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In shouldDisableUninstallButton of ApplicationActionButtonsPreferenceController.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28641"
    },
    {
      "rank": 389,
      "cve_id": "CVE-2026-28647",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In updateState of DeviceAdminAppsPreferenceController.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28647"
    },
    {
      "rank": 390,
      "cve_id": "CVE-2026-28648",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In Settings, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28648"
    },
    {
      "rank": 391,
      "cve_id": "CVE-2026-37719",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in dormakaba evolo Service (all versions) allows a remote attacker to execute arbitrary code as SYSTEM via a .NET component.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37719"
    },
    {
      "rank": 392,
      "cve_id": "CVE-2026-49880",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In multiple functions of nfa_nfcee_act.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49880"
    },
    {
      "rank": 393,
      "cve_id": "CVE-2026-78860",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in Mercusys AC12 V2 allows a local attacker to execute arbitrary code via the storage of information in plaintext",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78860"
    },
    {
      "rank": 394,
      "cve_id": "CVE-2026-78861",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in Mercusys AC12 V2 allows a local attacker to execute arbitrary code via a hardcoded 512-bit RSA Private Key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78861"
    },
    {
      "rank": 395,
      "cve_id": "CVE-2026-78862",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in Mercusys AC12 V2 allows a local attacker to execute arbitrary code via the UART serial interface on the printed circuit board (PCB)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78862"
    },
    {
      "rank": 396,
      "cve_id": "CVE-2026-82988",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Viewsonic",
      "product": "vCast",
      "cwe": null,
      "title": "CVE-2026-82988",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82988"
    },
    {
      "rank": 397,
      "cve_id": "CVE-2026-82989",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Viewsonic",
      "product": "vCast",
      "cwe": null,
      "title": "CVE-2026-82989",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82989"
    },
    {
      "rank": 398,
      "cve_id": "CVE-2026-88391",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Northstar (dromara/northstar, quantitative trading platform) <= 9.1.1 enables the H2 Console but its auth interceptor only covers /northstar/**, so /h2-console is exposed with no authentication and the embedded H2 DB uses default sa / empty password. Any network-reachable attacker can run arbitrary system commands via CREATE ALIAS (pre-auth RCE).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88391"
    },
    {
      "rank": 399,
      "cve_id": "CVE-2026-88392",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Unimall v4 is vulnerable to Directory Traversal in FileUploadController.local(). This allows an attacker to execute arbitrary code.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88392"
    },
    {
      "rank": 400,
      "cve_id": "CVE-2026-88393",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "WookTeam v1.6.6 and before is vulnerable to RCE in the project task export interface /api/project/task/export. The data parameter is base64-decoded and passed directly into the string2array() function in app/Module/Base.php, which executes eval(\"\\$array = $data;\") whenever the decoded string starts with array. An attacker can inject arbitrary PHP code into the eval call and achieve RCE.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88393"
    },
    {
      "rank": 401,
      "cve_id": "CVE-2026-88394",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "WookTeam v1.6.6 and before is vulnerable to a Directory Traversal. The project task export endpoint /api/project/task/export downloads an arbitrary file from the server when the data parameter is supplied with a crafted JSON payload. The file value inside the JSON is concatenated directly into storage_path($file) without any path normalization or directory boundary check, so directory traversal (../) escapes the storage/ directory and response()->download() streams any file readable by the web server process.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88394"
    },
    {
      "rank": 402,
      "cve_id": "CVE-2026-88396",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "ApiAdmin v5.0 and before is vulnerable to Directory Traversal. The admin file-upload endpoint POST /admin/Index/upload in ApiAdmin takes the uploaded file's extension verbatim there is no whitelist, blacklist or content check and move_uploaded_file() drops the file into the web-accessible directory public/upload/Ymd/. Any logged-in admin user can upload a .php file and reach it directly over HTTP, achieving remote code execution on the server.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88396"
    },
    {
      "rank": 403,
      "cve_id": "CVE-2026-88397",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "ApiAdmin v.5.0 and before is vulnerable to SQL Injection in the user-list endpoint GET /admin/User/getUsers via the gid parameter.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88397"
    },
    {
      "rank": 404,
      "cve_id": "CVE-2026-88424",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "FineAdmin v1.0 was discovered to contain a SQL injection vulnerability via the field/order parameter at ButtonService.GetListByFilter(). This vulnerability allows attackers to access sensitive database information via crafted SQL statements.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88424"
    },
    {
      "rank": 405,
      "cve_id": "CVE-2026-95165",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Bacularis 5.4.0 - 6.5.1 is vulnerable to Cross Site Scripting (XSS) in the Organization name field.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95165"
    },
    {
      "rank": 406,
      "cve_id": "CVE-2026-95166",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "In Bacularis v1.0.0 - 6.5.1 when adding a new pool, the LabelFormat field allows for a Cross Site Scripting (XSS) payload.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95166"
    },
    {
      "rank": 407,
      "cve_id": "CVE-2026-95263",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Feehi CMS 2.1.1 is vulnerable to Incorrect Access Control. A low-privilege backend administrator with administrator-update permission can change the password of the built-in super administrator account. The server does not enforce protection for this account, and the update scenario does not require the old password.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95263"
    },
    {
      "rank": 408,
      "cve_id": "CVE-2026-95264",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Feehi CMS 2.1.1 is vulnerable to Directory Traversal. An authenticated backend user with article edit permission can delete arbitrary files writable by the PHP process. Article image metadata is used to construct a filesystem path and is passed to `unlink()` without path traversal or directory validation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95264"
    },
    {
      "rank": 409,
      "cve_id": "CVE-2026-95265",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Feehi CMS 2.1.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the UEditor catchimage endpoint. The private-IP validation does not block loopback or link-local addresses, allowing an attacker to make the server probe internal HTTP services through response differences.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95265"
    },
    {
      "rank": 410,
      "cve_id": "CVE-2026-104711",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Struts",
      "cwe": "CWE-917",
      "title": "Apache Struts: OGNL injection in the legacy RESTful action mapper",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104711"
    },
    {
      "rank": 411,
      "cve_id": "CVE-2026-104712",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Struts",
      "cwe": "CWE-405",
      "title": "Apache Struts: Disproportionate response size when rendering BigDecimal request parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104712"
    },
    {
      "rank": 412,
      "cve_id": "CVE-2026-104713",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Struts",
      "cwe": "CWE-770",
      "title": "Apache Struts: Unbounded request body read in the REST plugin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104713"
    },
    {
      "rank": 413,
      "cve_id": "CVE-2026-104714",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Struts",
      "cwe": "CWE-362",
      "title": "Apache Struts: Shared message formatter exposes date and time values across concurrent requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104714"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2014-125130",
      "detail": "EXPLOIT PUBLISHED — CVE-2014-125130 (Damjan CodeArt Google MP3 Audio Player). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2023-39999",
      "detail": "EXPLOIT PUBLISHED — CVE-2023-39999 (WordPress.org WordPress). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2023-54402",
      "detail": "EXPLOIT PUBLISHED — CVE-2023-54402 (iDocView). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2023-54405",
      "detail": "EXPLOIT PUBLISHED — CVE-2023-54405 (H3C CVM). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2024-58388",
      "detail": "EXPLOIT PUBLISHED — CVE-2024-58388 (Sharp Corporation Multiple Multifunction Printers). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-56361",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-56361. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-56362",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-56362. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-56363",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-56363. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-56365",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-56365. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-100823",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-100823 (Mozilla Firefox). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-103534",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-103534 (David-Crty databasement). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-103539",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-103539 (ZongXR SuperMarket). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-103542",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-103542 (formtools.org Form Tools). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-103686",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-103686 (rhukster dom-sanitizer). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-104052",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-104052 (itsourcecode Pet Shop Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-104118",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-104118 (Unknown Razorpay for WooCommerce). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-104119",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-104119 (Unknown Simple Shopping Cart). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-104120",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-104120 (modelcontextprotocol mcp-server-fetch). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-104983",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-104983 (Linux Mint Xreader). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-105096",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-105096 (Omega Solution CoinEx Crypto). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-105097",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-105097 (Omega Solution CoinEx Crypto). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-105099",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-105099 (Omega Solution CoinEx Crypto). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-105137",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-105137 (Laradock). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-105147",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-105147 (SciPhi-AI R2R). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-105148",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-105148 (SciPhi-AI R2R). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-105156",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-105156 (YzmCMS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-105157",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-105157 (RainyGao DocSys). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-105158",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-105158 (RainyGao DocSys). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-105167",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-105167 (kishor-23 food-waste-management-system). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-17005",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-17005 (Unknown Horizontal scrolling announcements). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-37604",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-37604. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48521",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48521 (envoyproxy envoy). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-51879",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-51879. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73511",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73511 (envoyproxy envoy). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73512",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73512 (envoyproxy envoy). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73513",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73513 (envoyproxy envoy). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73546",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73546 (envoyproxy envoy). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73548",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73548 (envoyproxy envoy). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73550",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73550 (envoyproxy envoy). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73552",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73552 (envoyproxy envoy). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73553",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73553 (envoyproxy envoy). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86817",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86817 (Unknown Five Star Business Profile and Schema). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-93454",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-93454 (Webkul Aureus ERP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-93549",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-93549 (Unknown CoCart). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-97233",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-97233 (volotat Anagnorisis). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-97332",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-97332 (Unknown User Private Files). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-104286",
      "detail": "DUE DATE PASSED — CVE-2026-104286 (Fortinet FortiMail). CISA remediation deadline was October 4, 2026; still in catalog."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-56361",
      "detail": "RESCORED — CVE-2025-56361. CVSS 7.5 → 5.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-56362",
      "detail": "RESCORED — CVE-2025-56362. CVSS 7.5 → 5.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-56363",
      "detail": "RESCORED — CVE-2025-56363. CVSS 7.5 → 5.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-56364",
      "detail": "RESCORED — CVE-2025-56364. CVSS 7.5 → 5.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-56365",
      "detail": "RESCORED — CVE-2025-56365. CVSS 7.5 → 5.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-103101",
      "detail": "RESCORED — CVE-2026-103101 (Pexip Infinity). CVSS 8.6 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-103109",
      "detail": "RESCORED — CVE-2026-103109 (Pexip Infinity). CVSS 7.7 → 9.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-103489",
      "detail": "RESCORED — CVE-2026-103489 (JetBrains YouTrack). CVSS 2 → 5.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-103678",
      "detail": "RESCORED — CVE-2026-103678 (tnef). CVSS 5.4 → 8.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-103680",
      "detail": "RESCORED — CVE-2026-103680 (tnef). CVSS 3.1 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-105168",
      "detail": "RESCORED — CVE-2026-105168 (kishor-23 food-waste-management-system). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-105169",
      "detail": "RESCORED — CVE-2026-105169 (kishor-23 food-waste-management-system). CVSS 6.9 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-105170",
      "detail": "RESCORED — CVE-2026-105170 (kishor-23 food-waste-management-system). CVSS 6.9 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-105171",
      "detail": "RESCORED — CVE-2026-105171 (kishor-23 food-waste-management-system). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-37604",
      "detail": "RESCORED — CVE-2026-37604. CVSS 9.8 → 6.5 (NVD)."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-102628",
      "detail": "PATCH SHIPPED — CVE-2026-102628 (Eummena Cadmos LTI). Fixed in Cadmos LTI 2026-09-02."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-49329",
      "detail": "PATCH SHIPPED — CVE-2026-49329 (Red Hat OpenShift Container Platform 4.21). Fixed in Red Hat OpenShift Container Platform 4.21 1790707106."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-49762",
      "detail": "PATCH SHIPPED — CVE-2026-49762 (elixir-lang elixir). Fixed in elixir c64417d72fd5c7d09e963ca3ac5fa2b140978d9e."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-83589",
      "detail": "PATCH SHIPPED — CVE-2026-83589 (Red Hat OpenShift Container Platform 4.21). Fixed in Red Hat OpenShift Container Platform 4.21 1790706478."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-87114",
      "detail": "PATCH SHIPPED — CVE-2026-87114 (Red Hat OpenShift Container Platform 4.21). Fixed in Red Hat OpenShift Container Platform 4.21 1790707362."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-96577",
      "detail": "PATCH SHIPPED — CVE-2026-96577 (Red Hat OpenShift Container Platform 4.21). Fixed in Red Hat OpenShift Container Platform 4.21 1790777129."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64043",
      "detail": "ENRICHED — CVE-2026-64043 (Linux). Received CVSS 4.7 and CPE data from NVD."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
