{
  "day": "2026-10-06",
  "boundary": "UTC calendar day",
  "published_count": 1020,
  "by_severity": {
    "CRITICAL": 90,
    "HIGH": 346,
    "MEDIUM": 266,
    "LOW": 44
  },
  "kev_count": 0,
  "exploit_reference_count": 0,
  "awaiting_enrichment_count": 274,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-105484",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02128,
      "epss_percentile": 0.81335,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TOTOLINK",
      "product": "X6000R",
      "cwe": "CWE-77",
      "title": "TOTOLINK X6000R UploadFirmwareFile cstecgi.cgi firmware_check os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105484"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-105487",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.01089,
      "epss_percentile": 0.64238,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yogeshojha",
      "product": "reNgine",
      "cwe": "CWE-77",
      "title": "yogeshojha reNgine listTargets Endpoint tasks.py subdomain_discovery os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105487"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-32568",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00736,
      "epss_percentile": 0.52946,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JMAPlugins",
      "product": "WooCommerce Designer Pro",
      "cwe": "CWE-94",
      "title": "WordPress WooCommerce Designer Pro plugin <= 1.9.33 - Remote Code Execution (RCE) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32568"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-39725",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00736,
      "epss_percentile": 0.52946,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jonathan Horowitz",
      "product": "Content Visibility for Divi Builder",
      "cwe": "CWE-94",
      "title": "WordPress Content Visibility for Divi Builder plugin <= 5.03 - Remote Code Execution (RCE) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39725"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-105701",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0055,
      "epss_percentile": 0.44182,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mauro Cassani",
      "product": "ACPT (Premium)",
      "cwe": "CWE-434",
      "title": "ACPT (Premium) <= 2.0.66 - Authenticated (Subscriber+) Remote Code Execution via REST API Email Template",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105701"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-105486",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00495,
      "epss_percentile": 0.40445,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OSSRS",
      "product": "srs",
      "cwe": "CWE-287",
      "title": "OSSRS srs System API api.go systemAPI.Run missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105486"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-32579",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00486,
      "epss_percentile": 0.39828,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kognetiks",
      "product": "Kognetiks Chatbot for WordPress",
      "cwe": "CWE-434",
      "title": "WordPress Kognetiks Chatbot for WordPress plugin <= 2.4.9 - Arbitrary File Upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32579"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-39769",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00485,
      "epss_percentile": 0.39669,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Iqonic Design",
      "product": "Graphina",
      "cwe": "CWE-288",
      "title": "WordPress Graphina plugin <= 3.1.12 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39769"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-80327",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00484,
      "epss_percentile": 0.39612,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ping Identity",
      "product": "PingGateway",
      "cwe": "CWE-601",
      "title": "Open Redirect in PingGateway Fragment Filter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80327"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-39761",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00483,
      "epss_percentile": 0.39527,
      "kev": false,
      "kev_due_at": null,
      "vendor": "eLightUp",
      "product": "Meta Box AIO",
      "cwe": "CWE-266",
      "title": "WordPress Meta Box AIO plugin <= 3.7.1 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39761"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-39757",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00479,
      "epss_percentile": 0.39281,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AmentoTech",
      "product": "Taskbot",
      "cwe": "CWE-434",
      "title": "WordPress Taskbot plugin <= 6.6 - Arbitrary File Upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39757"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-39759",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00479,
      "epss_percentile": 0.39286,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AmentoTech",
      "product": "Workreap Core",
      "cwe": "CWE-434",
      "title": "WordPress Workreap Core plugin <= 3.4.5 - Arbitrary File Upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39759"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-105778",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00476,
      "epss_percentile": 0.39058,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "AC5",
      "cwe": "CWE-119",
      "title": "Tenda AC5 Wifi setWifi stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105778"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-39765",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00462,
      "epss_percentile": 0.37947,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebAppick",
      "product": "Challan",
      "cwe": "CWE-266",
      "title": "WordPress Challan plugin <= 3.7.88 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39765"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-48197",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00462,
      "epss_percentile": 0.37948,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PublishPress",
      "product": "PublishPress Capabilities",
      "cwe": "CWE-266",
      "title": "WordPress PublishPress Capabilities plugin <= 2.45.0 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48197"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-39753",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0045,
      "epss_percentile": 0.36993,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AmentoTech",
      "product": "Taskbot",
      "cwe": "CWE-266",
      "title": "WordPress Taskbot plugin <= 6.6 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39753"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-39752",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0045,
      "epss_percentile": 0.36967,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BlueGlass Interactive AG",
      "product": "Jobs for WordPress",
      "cwe": "CWE-22",
      "title": "WordPress Jobs for WordPress plugin <= 2.8.2 - Arbitrary File Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39752"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-39755",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00447,
      "epss_percentile": 0.36729,
      "kev": false,
      "kev_due_at": null,
      "vendor": "revmakx",
      "product": "WP Duplicate",
      "cwe": "CWE-434",
      "title": "WordPress WP Duplicate plugin <= 1.1.11 - Arbitrary File Upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39755"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-39770",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00423,
      "epss_percentile": 0.34515,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AmentoTech",
      "product": "Doctreat",
      "cwe": "CWE-434",
      "title": "WordPress Doctreat theme <= 1.7.0 - Arbitrary File Upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39770"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-39793",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00423,
      "epss_percentile": 0.34472,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nicu Micle",
      "product": "Simple JWT Login",
      "cwe": "CWE-288",
      "title": "WordPress Simple JWT Login plugin 4.0.0 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39793"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-39767",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00411,
      "epss_percentile": 0.33164,
      "kev": false,
      "kev_due_at": null,
      "vendor": "baseapp",
      "product": "WPBase Cache",
      "cwe": "CWE-770",
      "title": "WordPress WPBase Cache plugin <= 5.5.6 - Denial of Service Attack vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39767"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-104399",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0041,
      "epss_percentile": 0.33022,
      "kev": false,
      "kev_due_at": null,
      "vendor": "StylemixThemes",
      "product": "Motors",
      "cwe": "CWE-201",
      "title": "WordPress Motors plugin <= 1.4.124 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104399"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-105071",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00398,
      "epss_percentile": 0.31772,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Royal Plugins",
      "product": "SiteVault – Backup, Restore, Migration &amp; Cloning",
      "cwe": "CWE-201",
      "title": "WordPress SiteVault – Backup, Restore, Migration & Cloning plugin <= 1.5.17 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105071"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-105704",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00397,
      "epss_percentile": 0.31689,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Drug Recommendation System",
      "cwe": "CWE-287",
      "title": "SourceCodester Drug Recommendation System Auth Guard improper authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105704"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-39794",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00394,
      "epss_percentile": 0.31332,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WC Lovers",
      "product": "WooCommerce Multivendor Marketplace – REST API",
      "cwe": "CWE-862",
      "title": "WordPress WooCommerce Multivendor Marketplace – REST API plugin <= 1.6.3 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39794"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-48199",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00394,
      "epss_percentile": 0.31323,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Beplusthemes",
      "product": "Sermon'e",
      "cwe": "CWE-862",
      "title": "WordPress Sermon'e plugin <= 1.0.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48199"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-39776",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00384,
      "epss_percentile": 0.30218,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpshopmart",
      "product": "Tabs",
      "cwe": "CWE-94",
      "title": "WordPress Tabs plugin <= 2.5 - Remote Code Execution (RCE) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39776"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-32557",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00383,
      "epss_percentile": 0.30134,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bot Verification bookingwp.com: Verifying that you are not a robot...",
      "product": "WooCommerce Appointments",
      "cwe": "CWE-89",
      "title": "WordPress WooCommerce Appointments plugin <= 5.3.2 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32557"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-39746",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00383,
      "epss_percentile": 0.30134,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fs-code",
      "product": "Booknetic",
      "cwe": "CWE-89",
      "title": "WordPress Booknetic plugin <= 4.8.5 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39746"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-85153",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00371,
      "epss_percentile": 0.28878,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Schmooze",
      "product": "Schmooze dating mobile Application",
      "cwe": "CWE-321",
      "title": "Information Disclosure Vulnerability in Schmooze dating mobile Application",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85153"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-39792",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0036,
      "epss_percentile": 0.27599,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mitchell Bennis",
      "product": "Simple File List",
      "cwe": "CWE-22",
      "title": "WordPress Simple File List plugin <= 6.3.11 - Arbitrary File Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39792"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-39772",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00357,
      "epss_percentile": 0.27339,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bestwebsoft",
      "product": "Captcha by BestWebSoft",
      "cwe": "CWE-290",
      "title": "WordPress Captcha by BestWebSoft plugin <= 5.2.8 - Bypass Vulnerability vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39772"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-105059",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00352,
      "epss_percentile": 0.26707,
      "kev": false,
      "kev_due_at": null,
      "vendor": "royalnavneet",
      "product": "Delete All Comments of wordpress",
      "cwe": "CWE-862",
      "title": "WordPress Delete All Comments of wordpress plugin <= 7.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105059"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-94293",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00349,
      "epss_percentile": 0.2635,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Murrelektronik",
      "product": "Software AAS Edge Client all versions",
      "cwe": "CWE-306",
      "title": "Missing authentication for critical function in the aas-edge-client REST API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94293"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-25433",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00348,
      "epss_percentile": 0.2624,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tobias @Saleswonder.biz",
      "product": "WP2LEADS",
      "cwe": "CWE-862",
      "title": "WordPress WP2LEADS plugin <= 3.5.7 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25433"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-105809",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00348,
      "epss_percentile": 0.26185,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Simple Student Information System",
      "cwe": "CWE-79",
      "title": "SourceCodester Simple Student Information System Profile Field register.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105809"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-59358",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00346,
      "epss_percentile": 0.25917,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cloud Foundry",
      "product": "UAA",
      "cwe": "CWE-287",
      "title": "UAA OAuth Token Endpoint Vulnerability allows user access token reuse for client_credentials grant type",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59358"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-25434",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00342,
      "epss_percentile": 0.25559,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tobias @Saleswonder.biz",
      "product": "WP2LEADS",
      "cwe": "CWE-89",
      "title": "WordPress WP2LEADS plugin <= 3.5.7 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25434"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-39747",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00342,
      "epss_percentile": 0.25559,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WofficeIO",
      "product": "Woffice",
      "cwe": "CWE-89",
      "title": "WordPress Woffice theme <= 5.4.35 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39747"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-39775",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.25102,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DexignZone",
      "product": "JobZilla - Job Board WordPress Theme",
      "cwe": "CWE-266",
      "title": "WordPress JobZilla - Job Board WordPress Theme theme <= 2.2 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39775"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-62072",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.25101,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Planner",
      "product": "Progress Planner",
      "cwe": "CWE-862",
      "title": "WordPress Progress Planner plugin <= 1.10.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62072"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-39797",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00336,
      "epss_percentile": 0.24857,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Data443 Risk Mitigation, Inc.",
      "product": "GDPR Framework By Data443",
      "cwe": "CWE-502",
      "title": "WordPress GDPR Framework By Data443 plugin <= 2.5.0 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39797"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-39729",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00336,
      "epss_percentile": 0.24803,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WisdmLabs",
      "product": "Edwiser Bridge",
      "cwe": "CWE-201",
      "title": "WordPress Edwiser Bridge plugin <= 4.3.4 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39729"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-39762",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00332,
      "epss_percentile": 0.24282,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Patterns In The Cloud",
      "product": "Autoship Cloud for WooCommerce Subscription Products",
      "cwe": "CWE-862",
      "title": "WordPress Autoship Cloud for WooCommerce Subscription Products plugin <= 2.17.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39762"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-42637",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00332,
      "epss_percentile": 0.24278,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Payplug",
      "product": "PayPlug for WooCommerce (Official)",
      "cwe": "CWE-862",
      "title": "WordPress PayPlug for WooCommerce (Official) plugin <= 3.1.0 - Settings Change vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42637"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-105707",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00329,
      "epss_percentile": 0.23816,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "uptrace",
      "cwe": "CWE-200",
      "title": "uptrace user_handler.go Login information exposure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105707"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-39754",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00328,
      "epss_percentile": 0.23796,
      "kev": false,
      "kev_due_at": null,
      "vendor": "About Piotnet",
      "product": "Piotnet Addons For Elementor",
      "cwe": "CWE-22",
      "title": "WordPress Piotnet Addons For Elementor plugin <= 7.1.71 - Arbitrary File Download vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39754"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-105776",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00328,
      "epss_percentile": 0.2379,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bhagya3929",
      "product": "Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL",
      "cwe": "CWE-74",
      "title": "bhagya3929 Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL admin_transaction.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105776"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-39795",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00325,
      "epss_percentile": 0.23396,
      "kev": false,
      "kev_due_at": null,
      "vendor": "brewlabs",
      "product": "SendPress Newsletters",
      "cwe": "CWE-89",
      "title": "WordPress SendPress Newsletters plugin <= 1.26.1.20 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39795"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-42417",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00325,
      "epss_percentile": 0.23397,
      "kev": false,
      "kev_due_at": null,
      "vendor": "reputeinfosystems",
      "product": "ARMember Premium",
      "cwe": "CWE-89",
      "title": "WordPress ARMember Premium plugin <= 7.8 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42417"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-39751",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00323,
      "epss_percentile": 0.23222,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Payplug",
      "product": "PayPlug for WooCommerce (Official)",
      "cwe": "CWE-862",
      "title": "WordPress PayPlug for WooCommerce (Official) plugin <= 3.1.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39751"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-104387",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00318,
      "epss_percentile": 0.22662,
      "kev": false,
      "kev_due_at": null,
      "vendor": "blubrry",
      "product": "PowerPress Podcasting",
      "cwe": "CWE-862",
      "title": "WordPress PowerPress Podcasting plugin <= 11.17.9 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104387"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-41559",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.22406,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pluginjoy",
      "product": "SafeSnap – Verified WordPress Backup &amp; Restore",
      "cwe": "CWE-201",
      "title": "WordPress SafeSnap – Verified WordPress Backup & Restore plugin <= 2.1.2 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41559"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-41561",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.22406,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adrian Lin",
      "product": "Museder RestoreOne",
      "cwe": "CWE-201",
      "title": "WordPress Museder RestoreOne plugin <= 2.7.276 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41561"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-41562",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.22407,
      "kev": false,
      "kev_due_at": null,
      "vendor": "norvisgabriel",
      "product": "Norvis Backup",
      "cwe": "CWE-201",
      "title": "WordPress Norvis Backup plugin <= 1.1.0 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41562"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-42413",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.22407,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DaftPlug",
      "product": "Snapshotify &#8211; All-in-One Backup &amp; Restore &amp; Migrate",
      "cwe": "CWE-201",
      "title": "WordPress Snapshotify – All-in-One Backup & Restore & Migrate plugin <= 1.3.2 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42413"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-104757",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.22485,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Javier Carazo",
      "product": "Import and export users and customers",
      "cwe": "CWE-266",
      "title": "WordPress Import and export users and customers plugin <= 2.5.5 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104757"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-105058",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00315,
      "epss_percentile": 0.22357,
      "kev": false,
      "kev_due_at": null,
      "vendor": "John James Jacoby",
      "product": "WP User Profiles",
      "cwe": "CWE-266",
      "title": "WordPress WP User Profiles plugin <= 2.7.3 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105058"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-105057",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00315,
      "epss_percentile": 0.22283,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ben Marshall",
      "product": "Zero Spam",
      "cwe": "CWE-290",
      "title": "WordPress Zero Spam plugin <= 5.7.11 - Bypass vulnerability vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105057"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-92821",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0031,
      "epss_percentile": 0.21813,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-393",
      "title": "Sssd: sssd: access control bypass via premature ldap access rule evaluation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92821"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-32578",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00307,
      "epss_percentile": 0.21469,
      "kev": false,
      "kev_due_at": null,
      "vendor": "techsupport",
      "product": "ECPay Ecommerce for WooCommerce",
      "cwe": "CWE-862",
      "title": "WordPress ECPay Ecommerce for WooCommerce plugin <= 1.1.2606090 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32578"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-39730",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00307,
      "epss_percentile": 0.2147,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Marcin",
      "product": "Wise Chat",
      "cwe": "CWE-862",
      "title": "WordPress Wise Chat plugin <= 3.4.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39730"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-32580",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00306,
      "epss_percentile": 0.214,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpgenie",
      "product": "WooCommerce Lottery",
      "cwe": "CWE-89",
      "title": "WordPress WooCommerce Lottery plugin <= 2.2.9 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32580"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-39764",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00304,
      "epss_percentile": 0.212,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RadiusTheme",
      "product": "Radius Booking — Booking Calendar for Appointments &amp; Services",
      "cwe": "CWE-89",
      "title": "WordPress Radius Booking — Booking Calendar for Appointments & Services plugin <= 1.0.19 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39764"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-102387",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.21008,
      "kev": false,
      "kev_due_at": null,
      "vendor": "XServer",
      "product": "Xserver Migrator",
      "cwe": "CWE-497",
      "title": "WordPress Xserver Migrator plugin <= 1.6.6 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102387"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-104385",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.21007,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adrian Tobey",
      "product": "Groundhogg",
      "cwe": "CWE-201",
      "title": "WordPress Groundhogg plugin <= 4.8.3 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104385"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-4889",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00299,
      "epss_percentile": 0.20668,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RDL Technologies",
      "product": "eLoanApp Platform",
      "cwe": "CWE-89",
      "title": "SQL Injection (SQLi) in eLoanApp Platform by RDL Technologies",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4889"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-39796",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00299,
      "epss_percentile": 0.20667,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Flipper Code – WordPress Development Company",
      "product": "Advanced Posts Listing – Show Post List Easily",
      "cwe": "CWE-862",
      "title": "WordPress Advanced Posts Listing – Show Post List Easily plugin <= 1.0.8 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39796"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-41560",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00299,
      "epss_percentile": 0.20667,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wxdlabs",
      "product": "WXD Backup Lite",
      "cwe": "CWE-862",
      "title": "WordPress WXD Backup Lite plugin <= 1.0.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41560"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-66588",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00299,
      "epss_percentile": 0.20667,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dream-Theme",
      "product": "The7",
      "cwe": "CWE-862",
      "title": "WordPress The7 theme <= 14.2.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66588"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-105775",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00296,
      "epss_percentile": 0.20331,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vLLM",
      "cwe": "CWE-119",
      "title": "vllm-project vLLM Completions Request mamba_mixer2.py conv_ssm_forward out-of-bounds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105775"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-105070",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00294,
      "epss_percentile": 0.20046,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dimitri Grassi",
      "product": "Salon booking system",
      "cwe": "CWE-266",
      "title": "WordPress Salon booking system plugin <= 10.31.7 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105070"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-39771",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0029,
      "epss_percentile": 0.1967,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MightyNetworks vs BuddyBoss",
      "product": "Buddyboss Platform",
      "cwe": "CWE-89",
      "title": "WordPress Buddyboss Platform plugin <= 3.1.0 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39771"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-42414",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0029,
      "epss_percentile": 0.19669,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CridioStudio",
      "product": "ListingPro",
      "cwe": "CWE-89",
      "title": "WordPress ListingPro plugin <= 2.9.12 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42414"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-42416",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0029,
      "epss_percentile": 0.19669,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AndonDesign",
      "product": "UDesign Core",
      "cwe": "CWE-89",
      "title": "WordPress UDesign Core plugin <= 4.15.0 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42416"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-39787",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0029,
      "epss_percentile": 0.19655,
      "kev": false,
      "kev_due_at": null,
      "vendor": "10Web",
      "product": "10Web Social Photo Feed",
      "cwe": "CWE-862",
      "title": "WordPress 10Web Social Photo Feed plugin <= 1.4.35 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39787"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-39773",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00288,
      "epss_percentile": 0.19486,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AmentoTech",
      "product": "Doctreat Core",
      "cwe": "CWE-266",
      "title": "WordPress Doctreat Core plugin <= 1.7.0 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39773"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-104406",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00288,
      "epss_percentile": 0.19509,
      "kev": false,
      "kev_due_at": null,
      "vendor": "picu",
      "product": "picu",
      "cwe": "CWE-862",
      "title": "WordPress picu plugin <= 3.10.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104406"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-104405",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00282,
      "epss_percentile": 0.18914,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nexcess",
      "product": "GiveWP",
      "cwe": "CWE-266",
      "title": "WordPress GiveWP plugin <= 4.17.0 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104405"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-39749",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00279,
      "epss_percentile": 0.18592,
      "kev": false,
      "kev_due_at": null,
      "vendor": "digitalpoint",
      "product": "App for Cloudflare®",
      "cwe": "CWE-862",
      "title": "WordPress App for Cloudflare® plugin <= 1.10.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39749"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-105317",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.18446,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cozmoslabs",
      "product": "Paid Member Subscriptions",
      "cwe": "CWE-89",
      "title": "WordPress Paid Member Subscriptions plugin <= 3.1.1 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105317"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-75962",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.1849,
      "kev": false,
      "kev_due_at": null,
      "vendor": "saadiqbal",
      "product": "Post SMTP – Complete Email Delivery and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App",
      "cwe": "CWE-79",
      "title": "Post SMTP <= 4.0.1 - Unauthenticated Stored DOM-Based Cross-Site Scripting via 'user_email' Parameter (Multisite Registration → Failed Email Log)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75962"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-105571",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00278,
      "epss_percentile": 0.18503,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "PickMall Lilishop",
      "cwe": "CWE-266",
      "title": "PickMall Lilishop Mobile Binding bindMobile improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105571"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-32581",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00274,
      "epss_percentile": 0.18035,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mooberrydreams",
      "product": "Mooberry Book Manager",
      "cwe": "CWE-89",
      "title": "WordPress Mooberry Book Manager plugin 4.16.2 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32581"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-105705",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00273,
      "epss_percentile": 0.17957,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Drug Recommendation System",
      "cwe": "CWE-79",
      "title": "SourceCodester Drug Recommendation System add_drug.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105705"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-105708",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00273,
      "epss_percentile": 0.17959,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "imgproxy",
      "cwe": "CWE-79",
      "title": "imgproxy SVG svg.go sanitizeElement cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105708"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-98184",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00271,
      "epss_percentile": 0.17626,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mwifiex: prevent authentication frame length truncation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98184"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-42638",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.16632,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Awesomemotive",
      "product": "Easy Digital Downloads",
      "cwe": "CWE-862",
      "title": "WordPress Easy Digital Downloads plugin <= 3.7.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42638"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-57546",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.16526,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-126",
      "title": "Buffer Over-read in WLAN HAL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57546"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-105807",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.16579,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Simple Student Information System",
      "cwe": "CWE-74",
      "title": "SourceCodester Simple Student Information System searchquery.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105807"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-105808",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00263,
      "epss_percentile": 0.16631,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Simple Student Information System",
      "cwe": "CWE-79",
      "title": "SourceCodester Simple Student Information System searchresults.php clean cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105808"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-41558",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00259,
      "epss_percentile": 0.16068,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Synchro",
      "product": "WP Migration Plugin DB & Files – WP Synchro",
      "cwe": "CWE-290",
      "title": "WordPress WP Migration Plugin DB & Files – WP Synchro plugin <= 1.16.1 - 2FA Bypass vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41558"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-104747",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00257,
      "epss_percentile": 0.15895,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edge-Themes",
      "product": "Haaken",
      "cwe": "CWE-502",
      "title": "WordPress Haaken theme <= 1.5 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104747"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-94206",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00256,
      "epss_percentile": 0.15724,
      "kev": false,
      "kev_due_at": null,
      "vendor": "danielberkompas",
      "product": "cloak_ecto",
      "cwe": "CWE-916",
      "title": "Cloak PBKDF2 field ignores the configured iteration count and runs only :size rounds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94206"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-100518",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00256,
      "epss_percentile": 0.15787,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebFactory",
      "product": "Advanced Google reCAPTCHA",
      "cwe": "CWE-288",
      "title": "WordPress Advanced Google reCAPTCHA plugin <= 5.40 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100518"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-39719",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00255,
      "epss_percentile": 0.15609,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DeKnows",
      "product": "PDF Smart Viewer for Elementor",
      "cwe": "CWE-918",
      "title": "WordPress PDF Smart Viewer for Elementor plugin <= 1.0.4 - Server Side Request Forgery (SSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39719"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-39728",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00255,
      "epss_percentile": 0.1561,
      "kev": false,
      "kev_due_at": null,
      "vendor": "instapagedev",
      "product": "Instapage Plugin",
      "cwe": "CWE-918",
      "title": "WordPress Instapage Plugin plugin <= 3.7.2 - Server Side Request Forgery (SSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39728"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-39756",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00255,
      "epss_percentile": 0.1561,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wappointment team",
      "product": "Wappointment",
      "cwe": "CWE-639",
      "title": "WordPress Wappointment plugin <= 2.7.7 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39756"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-39798",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00253,
      "epss_percentile": 0.15309,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemetechMount",
      "product": "TrueBooker",
      "cwe": "CWE-862",
      "title": "WordPress TrueBooker plugin <= 1.2.9 - Settings Change vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39798"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-39758",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00251,
      "epss_percentile": 0.15137,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Midtrans",
      "product": "Midtrans-WooCommerce",
      "cwe": "CWE-79",
      "title": "WordPress Midtrans-WooCommerce plugin <= 2.32.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39758"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-39766",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00251,
      "epss_percentile": 0.15141,
      "kev": false,
      "kev_due_at": null,
      "vendor": "reputeinfosystems",
      "product": "ARForms",
      "cwe": "CWE-79",
      "title": "WordPress ARForms plugin <= 7.1.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39766"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-39790",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00251,
      "epss_percentile": 0.1511,
      "kev": false,
      "kev_due_at": null,
      "vendor": "e4jvikwp",
      "product": "VikRentCar",
      "cwe": "CWE-79",
      "title": "WordPress VikRentCar plugin <= 1.4.6 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39790"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-42418",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00251,
      "epss_percentile": 0.15099,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Socialrocket",
      "product": "Social Rocket",
      "cwe": "CWE-79",
      "title": "WordPress Social Rocket plugin <= 1.3.5 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42418"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-42634",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00251,
      "epss_percentile": 0.15139,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bPlugins",
      "product": "Video Background Block – Use video as background in the section.",
      "cwe": "CWE-79",
      "title": "WordPress Video Background Block – Use video as background in the section. plugin <= 2.0.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42634"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-42635",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00251,
      "epss_percentile": 0.15139,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpgenie",
      "product": "WooCommerce Simple Auctions",
      "cwe": "CWE-79",
      "title": "WordPress WooCommerce Simple Auctions plugin <= 3.0.10 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42635"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-42636",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00251,
      "epss_percentile": 0.15139,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Legal Pages",
      "product": "WP Cookie Notice for GDPR, CCPA & ePrivacy Consent",
      "cwe": "CWE-79",
      "title": "WordPress WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin <= 4.4.6 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42636"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-39791",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.15025,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mailjet",
      "product": "Mailjet Email Marketing",
      "cwe": "CWE-201",
      "title": "WordPress Mailjet Email Marketing plugin <= 6.2.3 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39791"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-39774",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00249,
      "epss_percentile": 0.14788,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tourfic AI Studio",
      "product": "Tourfic Pro",
      "cwe": "CWE-266",
      "title": "WordPress Tourfic Pro plugin <= 1.17.3 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39774"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-39785",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00247,
      "epss_percentile": 0.14579,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Serhii Pasyuk",
      "product": "Gmedia Photo Gallery",
      "cwe": "CWE-89",
      "title": "WordPress Gmedia Photo Gallery plugin <= 1.25.1 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39785"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-41555",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00247,
      "epss_percentile": 0.14579,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Weblizar – WordPress Themes & Plugin",
      "product": "Newsletter Subscription Form – User Subscriptions Form, Capture Email",
      "cwe": "CWE-89",
      "title": "WordPress Newsletter Subscription Form – User Subscriptions Form, Capture Email plugin <= 1.5.9 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41555"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-42415",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00247,
      "epss_percentile": 0.14579,
      "kev": false,
      "kev_due_at": null,
      "vendor": "p-themes",
      "product": "Porto Theme - Functionality",
      "cwe": "CWE-89",
      "title": "WordPress Porto Theme - Functionality plugin <= 3.9.3 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42415"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-41563",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00245,
      "epss_percentile": 0.14376,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dawer Drew",
      "product": "Sitemovr",
      "cwe": "CWE-201",
      "title": "WordPress Sitemovr plugin <= 1.0.1 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41563"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-105611",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.0024,
      "epss_percentile": 0.13851,
      "kev": false,
      "kev_due_at": null,
      "vendor": "chillzhuang",
      "product": "SpringBlade",
      "cwe": "CWE-266",
      "title": "chillzhuang SpringBlade User Detail Endpoint RoleController.java improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105611"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-32569",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.13422,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomunited",
      "product": "WP Media folder",
      "cwe": "CWE-79",
      "title": "WordPress WP Media folder plugin <= 6.2.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32569"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-32570",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.13417,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DaftPlug",
      "product": "Progressify - Progressive Web App (PWA)",
      "cwe": "CWE-79",
      "title": "WordPress Progressify - Progressive Web App (PWA) plugin <= 1.6.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32570"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-32572",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.13421,
      "kev": false,
      "kev_due_at": null,
      "vendor": "weDevs",
      "product": "WP User Frontend Pro",
      "cwe": "CWE-79",
      "title": "WordPress WP User Frontend Pro plugin <= 4.2.13 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32572"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-32574",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.13421,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EDGARROJAS",
      "product": "Smart Forms",
      "cwe": "CWE-79",
      "title": "WordPress Smart Forms plugin <= 2.6.104 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32574"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-32575",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.13419,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fantastic Plugins",
      "product": "SUMO Affiliates Pro",
      "cwe": "CWE-79",
      "title": "WordPress SUMO Affiliates Pro plugin <= 11.7.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32575"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-32577",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.1342,
      "kev": false,
      "kev_due_at": null,
      "vendor": "N-Media",
      "product": "Frontend File Manager",
      "cwe": "CWE-79",
      "title": "WordPress Frontend File Manager plugin <= 23.6 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32577"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-39720",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.13419,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mapster",
      "product": "Mapster WP Maps",
      "cwe": "CWE-79",
      "title": "WordPress Mapster WP Maps plugin <= 2.0.4 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39720"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-39722",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.1342,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VibeThemes",
      "product": "WPLMS",
      "cwe": "CWE-79",
      "title": "WordPress WPLMS theme <= 4.972 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39722"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-39724",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.13419,
      "kev": false,
      "kev_due_at": null,
      "vendor": "veppa",
      "product": "HTTP Requests Manager",
      "cwe": "CWE-79",
      "title": "WordPress HTTP Requests Manager plugin <= 1.3.11 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39724"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-39726",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.13421,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lumise NEO",
      "product": "Lumise Product Designer",
      "cwe": "CWE-79",
      "title": "WordPress Lumise Product Designer plugin <= 2.1.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39726"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-39731",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.13423,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code4life",
      "product": "Database for CF7",
      "cwe": "CWE-79",
      "title": "WordPress Database for CF7 plugin <= 1.2.6 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39731"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-39745",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.13423,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bestweblayout",
      "product": "Contact Form to DB by BestWebSoft",
      "cwe": "CWE-79",
      "title": "WordPress Contact Form to DB by BestWebSoft plugin <= 1.7.6 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39745"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-39748",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.1342,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeMove",
      "product": "EduMall",
      "cwe": "CWE-79",
      "title": "WordPress EduMall theme <= 4.5.3 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39748"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-39750",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.13422,
      "kev": false,
      "kev_due_at": null,
      "vendor": "weDevs",
      "product": "StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart",
      "cwe": "CWE-79",
      "title": "WordPress StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin <= 2.0.6 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39750"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-104394",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.13422,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Syed Balkhi",
      "product": "Charitable",
      "cwe": "CWE-79",
      "title": "WordPress Charitable plugin <= 1.8.12.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104394"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-104395",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.13422,
      "kev": false,
      "kev_due_at": null,
      "vendor": "picu",
      "product": "picu",
      "cwe": "CWE-79",
      "title": "WordPress picu plugin <= 3.10.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104395"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-104814",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.13418,
      "kev": false,
      "kev_due_at": null,
      "vendor": "epiphyt",
      "product": "Form Block",
      "cwe": "CWE-79",
      "title": "WordPress Form Block plugin <= 1.8.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104814"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-105061",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.13417,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bởi brandtoss",
      "product": "WP Mailster",
      "cwe": "CWE-79",
      "title": "WordPress WP Mailster plugin <= 1.9.0.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105061"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-95594",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00236,
      "epss_percentile": 0.13374,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cozy Vision Technologies Pvt. Ltd.",
      "product": "SMS Alert Order Notifications",
      "cwe": "CWE-266",
      "title": "WordPress SMS Alert Order Notifications plugin <= 4.0.0 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95594"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-105621",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0023,
      "epss_percentile": 0.12597,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jishenghua",
      "product": "jshERP",
      "cwe": "CWE-266",
      "title": "jishenghua jshERP Financial Receipt Update AccountHeadService.java updateAccountHeadAndDetail improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105621"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-95526",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00229,
      "epss_percentile": 0.12523,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RealMag777",
      "product": "BEAR",
      "cwe": "CWE-862",
      "title": "WordPress BEAR plugin <= 1.2.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95526"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-105573",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00229,
      "epss_percentile": 0.12544,
      "kev": false,
      "kev_due_at": null,
      "vendor": "newbee-ltd",
      "product": "newbee-mall",
      "cwe": "CWE-840",
      "title": "newbee-ltd newbee-mall Shopping Cart Quantity updateAccountHeadAndDetail logic error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105573"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-105610",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00227,
      "epss_percentile": 0.12297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "chillzhuang",
      "product": "SpringBlade",
      "cwe": "CWE-266",
      "title": "chillzhuang SpringBlade Parameter Submit Management ParamController.java improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105610"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-105703",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00227,
      "epss_percentile": 0.12297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PHPGurukul",
      "product": "User Registration & Login and User Management System",
      "cwe": "CWE-285",
      "title": "PHPGurukul User Registration & Login and User Management System Change Password change-password.php authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105703"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-102915",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00225,
      "epss_percentile": 0.12018,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Marco van Wieren",
      "product": "WPO365",
      "cwe": "CWE-862",
      "title": "WordPress WPO365 plugin <= 44.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102915"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-98167",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00225,
      "epss_percentile": 0.12116,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: client: fix server->total_read for compound encrypted PDUs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98167"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-39788",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00224,
      "epss_percentile": 0.1197,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shamim Hasan",
      "product": "Front End PM",
      "cwe": "CWE-79",
      "title": "WordPress Front End PM plugin <= 11.4.6 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39788"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-105572",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00223,
      "epss_percentile": 0.11768,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "PickMall Lilishop",
      "cwe": "CWE-285",
      "title": "PickMall Lilishop Buyer Invoice List receipt authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105572"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-98240",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00223,
      "epss_percentile": 0.11835,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: ip_tunnel: initialize `options_len` before referencing options",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98240"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-104038",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.11753,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-476",
      "title": "Sssd: sssd: denial of service via missing sid extension in certificate mapping",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104038"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-98311",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0022,
      "epss_percentile": 0.11372,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: virt_wifi: don't transfer operstate before register",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98311"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-98320",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0022,
      "epss_percentile": 0.11344,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfilter: flowtable: hold reference on ct until flow is released",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98320"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-98197",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0022,
      "epss_percentile": 0.11355,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "hwmon: (w83791d) remove fan/pwm 4-5 sysfs group on remove",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98197"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-98252",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0022,
      "epss_percentile": 0.11404,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/core: fix refcount bug in iwpm_get_nlmsg_request()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98252"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-98188",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0022,
      "epss_percentile": 0.11363,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: p54: validate curve data length in the calibration curve converters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98188"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-98209",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0022,
      "epss_percentile": 0.11352,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mmc: sdhci-of-aspeed: Remove children before releasing SDC resources",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98209"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-98233",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0022,
      "epss_percentile": 0.11362,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/packet: clear RX owner on VNET header error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98233"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-98234",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0022,
      "epss_percentile": 0.11362,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/sched: hhf: cap hh_flows_limit at change time",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98234"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-98275",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0022,
      "epss_percentile": 0.11356,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: ethernet: cortina: Ack RX overrun interrupt correctly",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98275"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-98319",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0022,
      "epss_percentile": 0.11344,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm: Fix drm_pending_vblank_event leak in error path for out_fence_ptr",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98319"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-98322",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0022,
      "epss_percentile": 0.11344,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfilter: nft_nat: fully initialise new_addr in netmap setup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98322"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-98214",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00219,
      "epss_percentile": 0.11283,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "selinux: recheck intermediate backing files on mprotect()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98214"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-98171",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00215,
      "epss_percentile": 0.10812,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98171"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-98169",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00215,
      "epss_percentile": 0.10812,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: client: fix potential OOB read in smb3_enum_snapshots()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98169"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-98172",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00215,
      "epss_percentile": 0.10799,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: client: fix smbd_connection leak on cifs_get_tcp_session() error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98172"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-98181",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00215,
      "epss_percentile": 0.10812,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/gud: fix out-of-bounds write in gud_plane_atomic_check()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98181"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-98199",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00215,
      "epss_percentile": 0.10799,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "hwmon: (pmbus/core) increase number of phases and add new mask",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98199"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-98213",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00215,
      "epss_percentile": 0.10808,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mmc: core: Cancel SDIO IRQ work before freeing host",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98213"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-98221",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00215,
      "epss_percentile": 0.10821,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KEYS: trusted: Fix tpm2_load_cmd() boundary check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98221"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-98247",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00215,
      "epss_percentile": 0.10821,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: hci_codec: validate vendor codec count length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98247"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-98264",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00215,
      "epss_percentile": 0.1083,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: virtio: reset device before deleting virtqueues",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98264"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-32571",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.10428,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Colabrio",
      "product": "Ohio Extra",
      "cwe": "CWE-79",
      "title": "WordPress Ohio Extra plugin <= 3.6.8 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32571"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-39727",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.10428,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Saravana Kumar K",
      "product": "WC Fields Factory",
      "cwe": "CWE-79",
      "title": "WordPress WC Fields Factory plugin <= 4.1.12 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39727"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-98229",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00209,
      "epss_percentile": 0.10066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfrm: save input state data before secpath resets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98229"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-98173",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00209,
      "epss_percentile": 0.1003,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: client: fix use-after-free of iface in cifs_try_adding_channels()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98173"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-98175",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00209,
      "epss_percentile": 0.10032,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: client: cancel reconnect work in clean_demultiplex_info()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98175"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-98230",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00209,
      "epss_percentile": 0.10066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfrm: use hlist_del_init_rcu for state_cache and state_cache_input",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98230"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-98168",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00209,
      "epss_percentile": 0.10033,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: client: fix reparse buffer bounds in cifs_query_reparse_point()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98168"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-98170",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00209,
      "epss_percentile": 0.10033,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: client: fix OOB struct field reads in move_smb2_ea_to_cifs()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98170"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-98211",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00209,
      "epss_percentile": 0.10067,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mmc: mmci: Fix use-after-free in busy-timeout work",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98211"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-98212",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00209,
      "epss_percentile": 0.10067,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mmc: hsq: Fix use-after-free in retry work",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98212"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-98215",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00209,
      "epss_percentile": 0.10066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "selinux: preserve user SID across nested backing files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98215"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-98222",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00209,
      "epss_percentile": 0.10065,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KEYS: encrypted: fix integer overflow of datablob_len",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98222"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-98231",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00209,
      "epss_percentile": 0.10066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfrm: serialize state GC with device state flush",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98231"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-98245",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00209,
      "epss_percentile": 0.10067,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "btrfs: take commit root semaphore when iterating in mark_block_group_to_copy()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98245"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-98248",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00209,
      "epss_percentile": 0.10052,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "arm64: percpu: Fix LSE operations on {8,16}-bit types",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98248"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-98266",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00209,
      "epss_percentile": 0.10062,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: core: Fix potential UAF after asynchronous card release",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98266"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-97300",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00207,
      "epss_percentile": 0.09849,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arraytics",
      "product": "WP Event Solution",
      "cwe": "CWE-799",
      "title": "WordPress WP Event Solution plugin <= 4.1.25 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97300"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-98180",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00206,
      "epss_percentile": 0.09767,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/msm: RCU-free the scheduler-containing ring and VM objects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98180"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-98244",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00206,
      "epss_percentile": 0.09759,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "btrfs: clear free space tree creation state on rebuild failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98244"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-98259",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00206,
      "epss_percentile": 0.09769,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fs/dax: check zero or empty entry before converting xarray entry",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98259"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-98296",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00206,
      "epss_percentile": 0.09766,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: btintel_pcie: validate TX skb length in send_sync",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98296"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-98272",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00203,
      "epss_percentile": 0.09406,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: mvpp2: prevent buffer overflow in page_pool allocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98272"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-39723",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00202,
      "epss_percentile": 0.09175,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Green Invoice",
      "product": "Morning for WooCommerce",
      "cwe": "CWE-862",
      "title": "WordPress Morning for WooCommerce plugin <= 2.4.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39723"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-39789",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00202,
      "epss_percentile": 0.09176,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Manage Ninja",
      "product": "Fluent Affiliate Pro",
      "cwe": "CWE-862",
      "title": "WordPress Fluent Affiliate Pro plugin <= 1.6.4 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39789"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-105072",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00202,
      "epss_percentile": 0.09176,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Manage Ninja",
      "product": "FluentBooking Pro",
      "cwe": "CWE-862",
      "title": "WordPress FluentBooking Pro plugin < 2.5.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105072"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-32576",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.09051,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZWEISCHNEIDER",
      "product": "Faktur Pro for WooCommerce",
      "cwe": "CWE-639",
      "title": "WordPress Faktur Pro for WooCommerce plugin <= 3.2.2 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32576"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-105472",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.09009,
      "kev": false,
      "kev_due_at": null,
      "vendor": "girishsaraf",
      "product": "Online-Appointment-Booking-System",
      "cwe": "CWE-74",
      "title": "girishsaraf Online-Appointment-Booking-System Booking book.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105472"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-98166",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00198,
      "epss_percentile": 0.08684,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/ttm: fix swapped-out resources never leaving their bulk_move range",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98166"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-98165",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00198,
      "epss_percentile": 0.08669,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu: restrict BAR0 fallback read to SR-IOV VFs only",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98165"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-98177",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00198,
      "epss_percentile": 0.08702,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdkfd: Avoid integer underflow in EOP ring size calculation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98177"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-98178",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00198,
      "epss_percentile": 0.08702,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu: Skip KFD mapping clear before initialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98178"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-98220",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00198,
      "epss_percentile": 0.08724,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "sched_ext: Fix NULL sched deref in kfunc sub-sched error paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98220"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-98242",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00198,
      "epss_percentile": 0.08693,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dma-buf: Fix silent overflow for phys vec to sgt",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98242"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-98268",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00198,
      "epss_percentile": 0.08673,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "perf: Fix null pointer access in is_include_guest_event()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98268"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-98350",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00196,
      "epss_percentile": 0.08521,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: brcmfmac: cyw: pass PMKID to firmware if present",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98350"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-104033",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.08204,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-193",
      "title": "Sssd: sssd: access control bypass via improper ldap shadow expiration check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104033"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-97308",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.08127,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebFactory",
      "product": "Login Lockdown",
      "cwe": "CWE-290",
      "title": "WordPress Login Lockdown plugin <= 2.17 - Bypass Vulnerability vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97308"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-39768",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00191,
      "epss_percentile": 0.07999,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CleanTalk Inc",
      "product": "Security & Malware scan by CleanTalk",
      "cwe": "CWE-79",
      "title": "WordPress Security & Malware scan by CleanTalk plugin <= 2.189 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39768"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-39778",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00191,
      "epss_percentile": 0.08,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themeansar",
      "product": "Ansar Import – One Click Starter Sites – for Elementor &amp; Themes",
      "cwe": "CWE-79",
      "title": "WordPress Ansar Import – One Click Starter Sites – for Elementor & Themes plugin <= 2.1.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39778"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-39780",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00191,
      "epss_percentile": 0.08,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Youzify",
      "product": "Youzify",
      "cwe": "CWE-79",
      "title": "WordPress Youzify plugin <= 1.3.7 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39780"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-39781",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00191,
      "epss_percentile": 0.08,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dan Rossiter",
      "product": "Document Gallery",
      "cwe": "CWE-79",
      "title": "WordPress Document Gallery plugin <= 5.1.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39781"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-39784",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00191,
      "epss_percentile": 0.07997,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nicdark",
      "product": "Hotel Booking",
      "cwe": "CWE-79",
      "title": "WordPress Hotel Booking plugin <= 3.8 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39784"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-40806",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00191,
      "epss_percentile": 0.07998,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Plugin Devs",
      "product": "Blog, Posts and Category Filter for Elementor",
      "cwe": "CWE-79",
      "title": "WordPress Blog, Posts and Category Filter for Elementor plugin <= 2.1.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40806"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-40807",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00191,
      "epss_percentile": 0.07998,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Aman",
      "product": "CF7 Views &#8211; Complete Entry Management for Contact Form 7",
      "cwe": "CWE-79",
      "title": "WordPress CF7 Views – Complete Entry Management for Contact Form 7 plugin <= 3.2.6 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40807"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-94675",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00191,
      "epss_percentile": 0.07998,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fluent Forms Free vs Pro",
      "product": "Fluent Forms Pro Add On Pack",
      "cwe": "CWE-79",
      "title": "WordPress Fluent Forms Pro Add On Pack plugin <= 6.2.13 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94675"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-105305",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00189,
      "epss_percentile": 0.07743,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-287",
      "title": "Keycloak-services: keycloak-services: device authorization grant bypasses per-client minimum.acr.value enforcement",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105305"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-98277",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00186,
      "epss_percentile": 0.07521,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "eth: fbnic: ring the doorbell if a burst ends in a drop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98277"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-59357",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00185,
      "epss_percentile": 0.07367,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cloud Foundry",
      "product": "UAA",
      "cwe": "CWE-345",
      "title": "Self-UAA OIDC Configuration allows JWT injection to establish unauthorized sessions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59357"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-98323",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00184,
      "epss_percentile": 0.07298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/siw: Bound fragmented header copies by the remaining length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98323"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-98282",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00184,
      "epss_percentile": 0.07305,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98282"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-98339",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00184,
      "epss_percentile": 0.07298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: cfg80211: don't filter by BSS type when removing stale entries",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98339"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-98241",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00184,
      "epss_percentile": 0.07302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipv6: xfrm: use full sockets in local error paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98241"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-98251",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00184,
      "epss_percentile": 0.07303,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "openvswitch: avoid reallocating confirmed conntrack labels",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98251"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-98253",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00184,
      "epss_percentile": 0.07301,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/ucma: Serialize join and leave on copy_to_user failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98253"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-98276",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00184,
      "epss_percentile": 0.07304,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: lock the socket in sock_gettstamp()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98276"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-98257",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00184,
      "epss_percentile": 0.07304,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "rds: ib: use rds_conn_drop() on protocol version mismatch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98257"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-98185",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00184,
      "epss_percentile": 0.073,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mwifiex: validate scan response extents",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98185"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-98186",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00184,
      "epss_percentile": 0.073,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mwifiex: bound the pairwise-cipher OUI walk to the IE length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98186"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-98187",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00184,
      "epss_percentile": 0.073,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: p54: require a full exp_if record in PDR_INTERFACE_LIST",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98187"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-98189",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00184,
      "epss_percentile": 0.07299,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: wilc1000: fix RX buffer OOB-write in wilc_wlan_handle_isr_ext()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98189"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-98190",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00184,
      "epss_percentile": 0.073,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: wilc1000: fix out-of-bounds read in P2P public action frames",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98190"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-98191",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00184,
      "epss_percentile": 0.07302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: wlcore: release runtime PM ref on regdomain config failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98191"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-98194",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00184,
      "epss_percentile": 0.07301,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: libertas_tf: fix UAF in lbtf_free_adapter()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98194"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-98195",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00184,
      "epss_percentile": 0.07301,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: iwlegacy: fix broadcast stations deallocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98195"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-98196",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00184,
      "epss_percentile": 0.07301,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: brcmsmac: fix UAF in brcms_free_timer()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98196"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-98201",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00184,
      "epss_percentile": 0.07302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Input: zero ff_effect before compat copy in input_ff_effect_from_user",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98201"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-98202",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00184,
      "epss_percentile": 0.07302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Input: synaptics-rmi4 - fix GPF in suspend and resume when unbound",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98202"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-98203",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00184,
      "epss_percentile": 0.07304,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Input: soc_button_array - check btns_desc->package.count",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98203"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-98204",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00184,
      "epss_percentile": 0.07304,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Input: rmi_smbus - fix out-of-bounds read in rmi_smb_write_block()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98204"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-98205",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00184,
      "epss_percentile": 0.07303,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Input: evdev - zero absinfo before partial copy in EVIOCSABS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98205"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-98207",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00184,
      "epss_percentile": 0.07303,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mmc: spi: reset bytes_xfered before retrying CRC failures",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98207"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-98208",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00184,
      "epss_percentile": 0.07306,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mmc: sdio_uart: fix xmit_fifo leak when the port table is full",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98208"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-98210",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00184,
      "epss_percentile": 0.07305,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mmc: mxcmmc: cancel data work and watchdog on remove",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98210"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-98217",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00184,
      "epss_percentile": 0.07299,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "IB/mlx4: Fix use-after-free on pkey sysfs registration failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98217"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-98255",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00184,
      "epss_percentile": 0.07305,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tcp: exclude old ACKs from tcp fast path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98255"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-98262",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00184,
      "epss_percentile": 0.07305,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ata: libahci: clear PxCLBU and PxFBU for AHCI_HFLAG_32BIT_ONLY",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98262"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-98298",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00184,
      "epss_percentile": 0.07306,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dmaengine: mmp_pdma: fix wrong sg length in mmp_pdma_prep_slave_sg()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98298"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-98299",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00184,
      "epss_percentile": 0.07296,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tcp: do not let tcp_rmem be set below 4096",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98299"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-98302",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00184,
      "epss_percentile": 0.07297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: fddi: skfp: fix NULL deref when setting the MAC address while down",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98302"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-98306",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00184,
      "epss_percentile": 0.07297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "seg6: set IPSKB_L3SLAVE from IP6SKB_L3SLAVE on IPIP decapsulation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98306"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-98308",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00184,
      "epss_percentile": 0.07297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: hda: trace PCM open only after assigning a stream",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98308"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-98314",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00184,
      "epss_percentile": 0.07297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: pcm: set timer->private_data before registering the PCM timer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98314"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-98317",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00184,
      "epss_percentile": 0.07257,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "neighbour: Enforce min/max to NDTPA_INTERVAL_PROBE_TIME_MS.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98317"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-98340",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00184,
      "epss_percentile": 0.07298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: cfg80211: only group hidden BSSes with beacon entries",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98340"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-98342",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00184,
      "epss_percentile": 0.07298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dmaengine: wait for RCU readers before releasing dma_device",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98342"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-98343",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00184,
      "epss_percentile": 0.07299,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dmaengine: fix use-after-free in dma_chan_put() and dma_release_channel()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98343"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-98344",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00184,
      "epss_percentile": 0.07299,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dmaengine: Fix device kref underflow in dma_chan_put()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98344"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-98345",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00184,
      "epss_percentile": 0.07296,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: cfg80211: check IP header size in cfg80211_classify8021d()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98345"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-98347",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00184,
      "epss_percentile": 0.07296,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "IB/IPoIB: Avoid restoring OPER_UP after multicast flush",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98347"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-98283",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.06919,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98283"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-98239",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.06919,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: lan743x: fix RX checksum use-after-free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98239"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-98369",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.06957,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfrm: add missing rcu_read_lock(), skb_dst_force() and dev_hold() for xfrm_trans_reinject()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98369"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-98290",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.06921,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: RFCOMM: avoid socket lock inversion in listener cleanup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98290"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-104670",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.06883,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThimPress",
      "product": "LearnPress",
      "cwe": "CWE-79",
      "title": "WordPress LearnPress plugin <= 4.4.9 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104670"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-104672",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.06884,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nexcess",
      "product": "GiveWP",
      "cwe": "CWE-79",
      "title": "WordPress GiveWP plugin <= 4.17.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104672"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-98331",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.06922,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mac80211: unlist vifs when their netdev is unregistered",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98331"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-98227",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0018,
      "epss_percentile": 0.06918,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "memstick: ms_block: destroy io_queue workqueue on removal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98227"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-98236",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0018,
      "epss_percentile": 0.06919,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: wwan: mhi_wwan_mbim: check skb_copy_bits() return value",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98236"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-98237",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0018,
      "epss_percentile": 0.0692,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: wwan: mhi_wwan_mbim: guard against a cyclic NDP chain",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98237"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-98238",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0018,
      "epss_percentile": 0.0692,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: wwan: t7xx: validate the netif index in t7xx_ccmni_recv_skb()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98238"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-98246",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0018,
      "epss_percentile": 0.06918,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: hci_sync: Serialize local codec list cleanup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98246"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-98249",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0018,
      "epss_percentile": 0.06917,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "arm64: hibernate: pass HVC_SET_VECTORS args to the resume hvc",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98249"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-98287",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0018,
      "epss_percentile": 0.0692,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "pppoatm: ensure a writable skb header and linear data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98287"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-98301",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0018,
      "epss_percentile": 0.06921,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: bridge: mst: move switchdev call outside rcu",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98301"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-98303",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0018,
      "epss_percentile": 0.06922,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipv4: icmp: reject RTN_UNREACHABLE input routes in icmp_route_lookup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98303"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-98312",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0018,
      "epss_percentile": 0.06918,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: 6fire: fix OOB write from device-reported iso length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98312"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-98316",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0018,
      "epss_percentile": 0.06919,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: bcd2000: Fix race between rawmidi and disconnect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98316"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-98325",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0018,
      "epss_percentile": 0.06921,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mac80211: set up the TX info early to fix failure paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98325"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-98326",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0018,
      "epss_percentile": 0.06922,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mac80211: mesh: release the channel if start fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98326"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-98328",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0018,
      "epss_percentile": 0.06918,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mac80211: add HE 6 GHz capability in the scan elems len",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98328"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-98278",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00179,
      "epss_percentile": 0.06805,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: remove WARN_ON_ONCE() from the dev_fill_forward_path() loop check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98278"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-98360",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00176,
      "epss_percentile": 0.06525,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/rxe: insert mcg into mcg_tree only after rxe_mcast_add() succeeds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98360"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-98300",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00176,
      "epss_percentile": 0.06563,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tcp: Don't call skb_clone_and_charge_r() for close()d listener in tcp_v6_do_rcv().",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98300"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-98261",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.06381,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "cifs: Fix server use-after-free in cifs_chan_skip_or_disable()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98261"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-98254",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.06379,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "swiotlb: use the adjusted address for the highmem page lookup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98254"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-98260",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.06383,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "exec: Cleanup POSIX timers right after de_thread()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98260"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-98174",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.06385,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: client: fix rlist race and missing initialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98174"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-98216",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.06386,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "IB/hfi1: Fix the PIO_CRED credit-return mmap",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98216"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-98179",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.06386,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu: fix rmmio iounmap skipped on device removal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98179"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-98182",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.06386,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mac80211: refuse to make a monitor active when it has no queue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98182"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-98192",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.06382,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: wcn36xx: Fix potential use-after-free in TX ack timer teardown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98192"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-98193",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.06382,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: libipw: reject TKIP frames without a full MIC",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98193"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-98198",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.06381,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "hwmon: (pwm-fan) Stop RPM timer before freeing tach data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98198"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-98200",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.06383,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "hwmon: (hp-wmi-sensors) Fix use-after-free in fungible_show()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98200"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-98206",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.06385,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Input: cyttsp5 - clamp the HID report size before memcpy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98206"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-98218",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.06379,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "i2c: atr: fix dangling adapter pointer on add failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98218"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-98232",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.06384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: core: Validate MODE SENSE lengths in scsi_cdl_enable()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98232"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-98235",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.06384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/sched: act_api: release tail references on DELACTION failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98235"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-98263",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.06385,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ASoC: codecs: rt712-sdca-dmic: fix uninitialized stream_config->type",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98263"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-98265",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.06379,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: usb-audio: Clamp implicit feedback packet count to URB capacity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98265"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-98267",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.06381,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "9p: Fix v9fs_issue_write() to update i_size and remote_i_size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98267"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-98269",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.0638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "btrfs: abort transaction on failure to update inode for hole punching and reflinking",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98269"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-98270",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.06383,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu: check ras and obj before dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98270"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-98271",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.06382,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: skbuff: do not leave stale header offsets after pskb_carve()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98271"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-98291",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.06383,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: btintel_pcie: fix off-by-one bounds check in RX submit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98291"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-98293",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.06387,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: ISO: Fix parent socket leak in iso_conn_ready()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98293"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-98295",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.06384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: coredump: Quiesce dump work on unregister",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98295"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-98297",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.06381,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: hci_core: Fix queuing tx_work after workqueue is drained",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98297"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-98307",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.06379,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: ath11k: cleanup arsta in ath11k_mac_peer_cleanup_all()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98307"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-98309",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.06384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/vc4: Use managed KMS polling to fix UAF on unbind",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98309"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-98327",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.06387,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mac80211: mesh: reset the CSA state when leaving",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98327"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-98329",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.06387,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mac80211: don't allow injecting frames wider than the chanctx",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98329"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-98334",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.0638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mac80211: reset state when starting AP fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98334"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-98335",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.0638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mac80211: abort chanswitch when leaving a mesh",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98335"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-98336",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.06386,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mac80211: don't offload TC setup on AP_VLAN interfaces",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98336"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-98337",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.0638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mac80211: don't start a ROC while scanning",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98337"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-98346",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.06385,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: cfg80211: don't get the radio mask for netdev-less wdevs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98346"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-32582",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.06279,
      "kev": false,
      "kev_due_at": null,
      "vendor": "iatoai",
      "product": "IATO MCP",
      "cwe": "CWE-862",
      "title": "WordPress IATO MCP plugin <= 1.11.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32582"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-98256",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00173,
      "epss_percentile": 0.06154,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "signal: Prevent exec() race",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98256"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-98258",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00173,
      "epss_percentile": 0.06152,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98258"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-98281",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00173,
      "epss_percentile": 0.0615,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "futex: Also allocate private hash on vfork()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98281"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-98341",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00173,
      "epss_percentile": 0.06154,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: cfg80211: don't free driver-owned scan requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98341"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-98330",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00173,
      "epss_percentile": 0.06152,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: cfg80211: get the wiphy out of a dying network namespace",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98330"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-98223",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00173,
      "epss_percentile": 0.06151,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm: filemap: retain mapped dropbehind folios",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98223"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-98224",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00173,
      "epss_percentile": 0.0615,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm/vma: correctly unaccount on mmap_prepare() failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98224"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-98226",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00173,
      "epss_percentile": 0.0615,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm, swap: fix SWAP_USAGE_OFFLIST_BIT collision with real usage count",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98226"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-98273",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00173,
      "epss_percentile": 0.06152,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "x86/kprobes: Fix crash when probing CS CALL instructions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98273"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-98274",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00173,
      "epss_percentile": 0.06151,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: psp: avoid conflicts with skb->decrypted and sk_validate_xmit_skb()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98274"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-98279",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00173,
      "epss_percentile": 0.0615,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "btrfs: handle lack of space when cleaning up verity items",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98279"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-98286",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00173,
      "epss_percentile": 0.06153,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drop_monitor: use timer_shutdown_sync() to prevent timer rearming during teardown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98286"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-98289",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00173,
      "epss_percentile": 0.06151,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "af_unix: Unify scc_index when finalising SCC in __unix_walk_scc().",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98289"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-98294",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00173,
      "epss_percentile": 0.06153,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: hci_qca: Do not write to the serial port after it is closed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98294"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-98304",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00173,
      "epss_percentile": 0.06153,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: bcmgenet: restore the hardware filters on open",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98304"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-98313",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00173,
      "epss_percentile": 0.06153,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/msm/dp: skip PUSH_IDLE when the link was never enabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98313"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-98321",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00173,
      "epss_percentile": 0.06151,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfilter: nf_nat: unregister and release hooks on error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98321"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-98367",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.05992,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/siw: Clear association under lock if siw_qp_modify fails in siw_accept",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98367"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-98348",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.05936,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: libipw: reject too-short association responses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98348"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-98349",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.05993,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: libipw: reject too-short beacon and probe responses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98349"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-98351",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00172,
      "epss_percentile": 0.05993,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: virt_wifi: free skb when disconnected",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98351"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-98354",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00172,
      "epss_percentile": 0.05935,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/mad: Fix receive buffer leak when PKey enforcement fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98354"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-98362",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00172,
      "epss_percentile": 0.05992,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "clk: scpi: bound-check DVFS index in scpi_dvfs_recalc_rate",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98362"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-98363",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00172,
      "epss_percentile": 0.05993,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "firmware: arm_scpi: reject DVFS OPP count above MAX_DVFS_OPPS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98363"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-98370",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00172,
      "epss_percentile": 0.05936,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfrm: fix compat ALLOCSPI request use-after-free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98370"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-105879",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.05913,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Crocoblock",
      "product": "JetElements For Elementor",
      "cwe": "CWE-79",
      "title": "WordPress JetElements For Elementor plugin <= 2.9.2.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105879"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-98368",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00168,
      "epss_percentile": 0.0556,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "esp: downgrade zerocopy managed frags before mutating skb frags",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98368"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-98359",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00168,
      "epss_percentile": 0.05488,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/core: Reject unregistering netdevs in ib_get_eth_speed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98359"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-98352",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.05488,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/rtrs-clt: Fix CQ pool leak when connect is interrupted",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98352"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-98365",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00165,
      "epss_percentile": 0.05126,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98365"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-98357",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00164,
      "epss_percentile": 0.0511,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "IB/isert: wait for deferred control PDU completions before releasing the connection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98357"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-98358",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00164,
      "epss_percentile": 0.05111,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "IB/iser: reject a remote invalidation of an unregistered direction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98358"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-98305",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00162,
      "epss_percentile": 0.04845,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: dsa: mxl862xx: disable the stats poll on teardown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98305"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-98315",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00162,
      "epss_percentile": 0.04842,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ntfs: protect runlist updates with the runlist lock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98315"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2026-98318",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00162,
      "epss_percentile": 0.04846,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: client: validate absolute native symlink targets before NT fixups",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98318"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-98324",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00162,
      "epss_percentile": 0.04846,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dmaengine: pxa: fix double counting of the hw descriptors",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98324"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-98361",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00162,
      "epss_percentile": 0.04803,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/rxe: Restore HMM_PFN_WRITE check in ODP write paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98361"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-98243",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00162,
      "epss_percentile": 0.04842,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dma-buf/dma-fence: fix checking signaling bit for timeline and driver name v3",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98243"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-98176",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00162,
      "epss_percentile": 0.04844,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdkfd: Avoid integer underflow with ffs in EOP ring size calc",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98176"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-98183",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00162,
      "epss_percentile": 0.04845,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mac80211: avoid out-of-bounds read for empty PREQ elements",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98183"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2026-98219",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00162,
      "epss_percentile": 0.04846,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "sched_ext: Close the pre-enable ops error claim window",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98219"
    },
    {
      "rank": 354,
      "cve_id": "CVE-2026-98225",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00162,
      "epss_percentile": 0.04845,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm/shrinker: fix bogus set_shrinker_bit() with cgroup.memory=nokmem",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98225"
    },
    {
      "rank": 355,
      "cve_id": "CVE-2026-98250",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00162,
      "epss_percentile": 0.04842,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: fix handling of NFSEXP_PNFS in the netlink codepath",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98250"
    },
    {
      "rank": 356,
      "cve_id": "CVE-2026-98280",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00162,
      "epss_percentile": 0.04844,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/xe/i2c: Disable IRQ on unbind",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98280"
    },
    {
      "rank": 357,
      "cve_id": "CVE-2026-98284",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00162,
      "epss_percentile": 0.04842,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netlink: do not free nlk->groups while lockless readers can use it",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98284"
    },
    {
      "rank": 358,
      "cve_id": "CVE-2026-98285",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00162,
      "epss_percentile": 0.04841,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: bridge: vlan: fix bugs caused by switchdev deletion errors",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98285"
    },
    {
      "rank": 359,
      "cve_id": "CVE-2026-98288",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00162,
      "epss_percentile": 0.04843,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: stmmac: fix TSO header length truncation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98288"
    },
    {
      "rank": 360,
      "cve_id": "CVE-2026-98292",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00162,
      "epss_percentile": 0.04843,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: btmtksdio, btmtkuart: validate WMT event length before struct access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98292"
    },
    {
      "rank": 361,
      "cve_id": "CVE-2026-98310",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00162,
      "epss_percentile": 0.04845,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/xe/shrinker: Take a runtime PM ref before shrinking non-system memory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98310"
    },
    {
      "rank": 362,
      "cve_id": "CVE-2026-98332",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00162,
      "epss_percentile": 0.04843,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mac80211: only operate on TDLS peers in the TDLS code",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98332"
    },
    {
      "rank": 363,
      "cve_id": "CVE-2026-98333",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00162,
      "epss_percentile": 0.04844,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mac80211: reset the LED state when ifup fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98333"
    },
    {
      "rank": 364,
      "cve_id": "CVE-2026-98338",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00162,
      "epss_percentile": 0.04843,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: cfg80211: ibss: ref BSS entry for joined event",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98338"
    },
    {
      "rank": 365,
      "cve_id": "CVE-2026-98356",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00161,
      "epss_percentile": 0.04706,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/bnxt_re: check create_singlethread_workqueue() in DCB setup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98356"
    },
    {
      "rank": 366,
      "cve_id": "CVE-2026-98371",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00161,
      "epss_percentile": 0.04706,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfrm: iptfs: fix runt reassembly panic from short inner tot_len",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98371"
    },
    {
      "rank": 367,
      "cve_id": "CVE-2026-98372",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00161,
      "epss_percentile": 0.04705,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfrm: iptfs: fix stack OOB read in iptfs_skb_reset_frag_walk()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98372"
    },
    {
      "rank": 368,
      "cve_id": "CVE-2026-105706",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00159,
      "epss_percentile": 0.04373,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Drug Recommendation System",
      "cwe": "CWE-352",
      "title": "SourceCodester Drug Recommendation System cross-site request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105706"
    },
    {
      "rank": 369,
      "cve_id": "CVE-2026-98366",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00156,
      "epss_percentile": 0.04155,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/rxe: validate access flags before swapping the MR's PD",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98366"
    },
    {
      "rank": 370,
      "cve_id": "CVE-2026-98228",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00155,
      "epss_percentile": 0.04067,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mips: select CONFIG_WEAK_REORDERING_BEYOND_LLSC from CONFIG_EYEQ",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98228"
    },
    {
      "rank": 371,
      "cve_id": "CVE-2026-98364",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00152,
      "epss_percentile": 0.03738,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfrm: hold net_device reference under RCU in bundle creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98364"
    },
    {
      "rank": 372,
      "cve_id": "CVE-2026-39599",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.0377,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wallstrdev",
      "product": "WDS MCP Content Manager",
      "cwe": "CWE-862",
      "title": "WordPress WDS MCP Content Manager plugin <= 3.10.4 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39599"
    },
    {
      "rank": 373,
      "cve_id": "CVE-2026-98353",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00151,
      "epss_percentile": 0.03703,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/erdma: Use IRQ-safe XArray helpers for QP and CQ tables",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98353"
    },
    {
      "rank": 374,
      "cve_id": "CVE-2026-98355",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00151,
      "epss_percentile": 0.03703,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/rtrs: guard against null kobj name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98355"
    },
    {
      "rank": 375,
      "cve_id": "CVE-2026-39760",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.03303,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Creative interactive media",
      "product": "Real 3D FlipBook",
      "cwe": "CWE-79",
      "title": "WordPress Real 3D FlipBook plugin <= 5.5 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39760"
    },
    {
      "rank": 376,
      "cve_id": "CVE-2026-103346",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.03308,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tomlister",
      "product": "Payflex Payment Gateway",
      "cwe": "CWE-79",
      "title": "WordPress Payflex Payment Gateway plugin <= 2.7.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103346"
    },
    {
      "rank": 377,
      "cve_id": "CVE-2026-86786",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.03265,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Slider Pro",
      "cwe": "CWE-200",
      "title": "Slider Pro <= 1.0.0 - Unauthenticated Sensitive Data Disclosure via sliderpro_multiple_images",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86786"
    },
    {
      "rank": 378,
      "cve_id": "CVE-2026-94299",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.02593,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "elegro Crypto Payment",
      "cwe": "CWE-863",
      "title": "elegro Crypto Payment <= 1.0.1 - Unauthenticated Arbitrary Order Status Change via IPN Callback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94299"
    },
    {
      "rank": 379,
      "cve_id": "CVE-2026-89289",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.02592,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Fast Courier",
      "cwe": "CWE-862",
      "title": "Fast Courier <= 5.2.3 - Unauthenticated Order Fulfillment Update via order-status-update REST Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89289"
    },
    {
      "rank": 380,
      "cve_id": "CVE-2026-94270",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.02592,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Deema Payment Gateway",
      "cwe": "CWE-287",
      "title": "Deema Payment Gateway <= 1.1.2 - Unauthenticated Payment Bypass and Order Manipulation via Webhook",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94270"
    },
    {
      "rank": 381,
      "cve_id": "CVE-2026-94271",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.02592,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Deema Payment Gateway",
      "cwe": "CWE-287",
      "title": "Deema Payment Gateway <= 1.1.2 - Unauthenticated Payment Confirmation Forgery via Unverified Success Return",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94271"
    },
    {
      "rank": 382,
      "cve_id": "CVE-2026-94278",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.02358,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "File Media Renamer",
      "cwe": "CWE-284",
      "title": "File Media Renamer <= 1.3 - Author+ Arbitrary File Rename via save-attachment-compat",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94278"
    },
    {
      "rank": 383,
      "cve_id": "CVE-2026-104380",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00129,
      "epss_percentile": 0.02178,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "Punk",
      "cwe": "CWE-1385",
      "title": "Punk versions from 0.48 before 0.55 for Perl route Extended CONNECT requests to any GET route without an Origin check in ps_serve_one",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104380"
    },
    {
      "rank": 384,
      "cve_id": "CVE-2026-57545",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.01628,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-822",
      "title": "Untrusted Pointer Dereference in Graphics",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57545"
    },
    {
      "rank": 385,
      "cve_id": "CVE-2026-104044",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0012,
      "epss_percentile": 0.01637,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-476",
      "title": "Sssd: sssd: denial of service via crafted passkey kerberos authentication request",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104044"
    },
    {
      "rank": 386,
      "cve_id": "CVE-2026-95105",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00115,
      "epss_percentile": 0.01413,
      "kev": false,
      "kev_due_at": null,
      "vendor": "danielberkompas",
      "product": "cloak",
      "cwe": "CWE-649",
      "title": "Cloak AES-CTR cipher lacks ciphertext authentication, allowing chosen-plaintext forgery by bit flipping",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95105"
    },
    {
      "rank": 387,
      "cve_id": "CVE-2026-25269",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00115,
      "epss_percentile": 0.01392,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-787",
      "title": "Out-of-bounds Write in Camera Driver",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25269"
    },
    {
      "rank": 388,
      "cve_id": "CVE-2026-25270",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00115,
      "epss_percentile": 0.01392,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-787",
      "title": "Out-of-bounds Write in Camera Driver",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25270"
    },
    {
      "rank": 389,
      "cve_id": "CVE-2026-25272",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00115,
      "epss_percentile": 0.01392,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-787",
      "title": "Out-of-bounds Write in Camera Driver",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25272"
    },
    {
      "rank": 390,
      "cve_id": "CVE-2026-25273",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00115,
      "epss_percentile": 0.01391,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-787",
      "title": "Out-of-bounds Write in Camera Driver",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25273"
    },
    {
      "rank": 391,
      "cve_id": "CVE-2026-25274",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00115,
      "epss_percentile": 0.01391,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-416",
      "title": "Use After Free in Windows WLAN Host",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25274"
    },
    {
      "rank": 392,
      "cve_id": "CVE-2026-25291",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0011,
      "epss_percentile": 0.01181,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-416",
      "title": "Use After Free in Graphics",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25291"
    },
    {
      "rank": 393,
      "cve_id": "CVE-2026-57537",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0011,
      "epss_percentile": 0.01181,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-416",
      "title": "Use After Free in DSP Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57537"
    },
    {
      "rank": 394,
      "cve_id": "CVE-2026-57554",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0011,
      "epss_percentile": 0.01181,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-416",
      "title": "Use After Free in DSP Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57554"
    },
    {
      "rank": 395,
      "cve_id": "CVE-2026-57555",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0011,
      "epss_percentile": 0.0118,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-416",
      "title": "Use After Free in DSP Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57555"
    },
    {
      "rank": 396,
      "cve_id": "CVE-2026-57559",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0011,
      "epss_percentile": 0.0118,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-416",
      "title": "Use After Free in DSP_Services",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57559"
    },
    {
      "rank": 397,
      "cve_id": "CVE-2026-104042",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01061,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-125",
      "title": "Sssd: sssd: denial of service via out-of-bounds read in pam responder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104042"
    },
    {
      "rank": 398,
      "cve_id": "CVE-2026-104039",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00102,
      "epss_percentile": 0.00862,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-825",
      "title": "Sssd: sssd: denial of service via stale connection state reuse in pam gssapi responder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104039"
    },
    {
      "rank": 399,
      "cve_id": "CVE-2026-25267",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00098,
      "epss_percentile": 0.00727,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-862",
      "title": "Missing Authorization in Core",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25267"
    },
    {
      "rank": 400,
      "cve_id": "CVE-2026-104040",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00096,
      "epss_percentile": 0.00675,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-140",
      "title": "Sssd: sssd: information disclosure via odata injection in entra id lookups",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104040"
    },
    {
      "rank": 401,
      "cve_id": "CVE-2026-104031",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00095,
      "epss_percentile": 0.00625,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-772",
      "title": "Sssd: sssd: denial of service via memory exhaustion in autofs responder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104031"
    },
    {
      "rank": 402,
      "cve_id": "CVE-2026-104032",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00095,
      "epss_percentile": 0.00625,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-408",
      "title": "Sssd: sssd: denial of service via unprivileged autofs cache invalidation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104032"
    },
    {
      "rank": 403,
      "cve_id": "CVE-2026-104035",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00095,
      "epss_percentile": 0.00625,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-772",
      "title": "Sssd: sssd: denial of service via memory exhaustion in kcm responder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104035"
    },
    {
      "rank": 404,
      "cve_id": "CVE-2026-104037",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00095,
      "epss_percentile": 0.00624,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-125",
      "title": "Sssd: sssd: denial of service via packet length underflow in autofs responder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104037"
    },
    {
      "rank": 405,
      "cve_id": "CVE-2026-104041",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00095,
      "epss_percentile": 0.00613,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-770",
      "title": "Sssd: sssd: denial of service via unbounded negative cache growth",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104041"
    },
    {
      "rank": 406,
      "cve_id": "CVE-2026-104043",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00095,
      "epss_percentile": 0.00613,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-125",
      "title": "Sssd: sssd: denial of service via undersized packet parsing in nss responder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104043"
    },
    {
      "rank": 407,
      "cve_id": "CVE-2026-25302",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00089,
      "epss_percentile": 0.00397,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-347",
      "title": "Improper Verification of Cryptographic Signature in Boot",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25302"
    },
    {
      "rank": 408,
      "cve_id": "CVE-2026-104036",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00089,
      "epss_percentile": 0.00375,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-787",
      "title": "Sssd: sssd: denial of service via out-of-bounds write in nfs idmap plugin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104036"
    },
    {
      "rank": 409,
      "cve_id": "CVE-2026-104034",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00089,
      "epss_percentile": 0.00374,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-825",
      "title": "Sssd: sssd: denial of service via use-after-free in kcm ticket renewal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104034"
    },
    {
      "rank": 410,
      "cve_id": "CVE-2026-25263",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00087,
      "epss_percentile": 0.00341,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-787",
      "title": "Out of Bounds write in Linux Camera",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25263"
    },
    {
      "rank": 411,
      "cve_id": "CVE-2026-63688",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Dell Container Storage Modules (CSM)",
      "cwe": "CWE-306",
      "title": "Dell Container Storage Modules (CSM), versions prior to v1.18.0, contains a Missing Authentication for Critical Function vulnerability in the csm-authorization-storage gRPC server. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to unauthorized access to storage backend administrator credentials for all registered storage arrays.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63688"
    },
    {
      "rank": 412,
      "cve_id": "CVE-2026-63692",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Container Storage Modules",
      "cwe": "CWE-306",
      "title": "Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63692"
    },
    {
      "rank": 413,
      "cve_id": "CVE-2026-105857",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "payloadcms",
      "product": "payload",
      "cwe": "CWE-94",
      "title": "Payload: RCE in Payload Form Builder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105857"
    },
    {
      "rank": 414,
      "cve_id": "CVE-2026-106102",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "quasarframework",
      "product": "quasar",
      "cwe": "CWE-79",
      "title": "Quasar Framework: Stored/Reflected XSS via unescaped SSR meta tag rendering in getHead()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106102"
    },
    {
      "rank": 415,
      "cve_id": "CVE-2026-67269",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Container Storage Modules (CSM)",
      "cwe": "CWE-269",
      "title": "Dell Container Storage Modules (CSM) Operator, versions prior to 1.18.0 contains an Improper Privilege Management vulnerability in the ContainerStorageModule Custom Resource reconciler. A low privileged remote attacker could potentially exploit this vulnerability, leading to escalation of privileges and gaining root-level access on cluster nodes.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67269"
    },
    {
      "rank": 416,
      "cve_id": "CVE-2026-79798",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "ClearPass Policy Manager (CPPM)",
      "cwe": null,
      "title": "Authenticated SQL Injection Vulnerabilities in ClearPass Policy Manager Web-Based Management Interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79798"
    },
    {
      "rank": 417,
      "cve_id": "CVE-2026-54472",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Container Storage Modules",
      "cwe": "CWE-798",
      "title": "Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use of Hard-coded Credentials vulnerability in the csm-docs. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.9.8",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54472"
    },
    {
      "rank": 418,
      "cve_id": "CVE-2026-55330",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-416",
      "title": "In BluetoothCccHandlerCallbackImpl of bluetooth_ccc.cc, there is a possible use-after-free due to a logic error in the code. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55330"
    },
    {
      "rank": 419,
      "cve_id": "CVE-2026-61421",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Container Storage Modules",
      "cwe": "CWE-798",
      "title": "Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use of Hard-coded Credentials vulnerability in the CSM Authorization. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61421"
    },
    {
      "rank": 420,
      "cve_id": "CVE-2026-76742",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "AOS-Switch (AOS-S)",
      "cwe": "CWE-269",
      "title": "Authentication Bypass in the Web Management Interface of AOS-S",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76742"
    },
    {
      "rank": 421,
      "cve_id": "CVE-2026-76743",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "AOS-Switch (AOS-S)",
      "cwe": null,
      "title": "Authentication Bypass Vulnerability in the Management Interface of AOS-S",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76743"
    },
    {
      "rank": 422,
      "cve_id": "CVE-2026-76744",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "AOS-Switch (AOS-S)",
      "cwe": null,
      "title": "Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-S",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76744"
    },
    {
      "rank": 423,
      "cve_id": "CVE-2026-76750",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "ClearPass Policy Manager (CPPM)",
      "cwe": null,
      "title": "Unauthenticated Deserialization of Untrusted Data allows Remote Code Execution in the Web Interface of HPE Networking ClearPass Policy Manager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76750"
    },
    {
      "rank": 424,
      "cve_id": "CVE-2026-76751",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "ClearPass Policy Manager (CPPM)",
      "cwe": null,
      "title": "Missing Integrity Verification in the OnGuard Agent of ClearPass Policy Manager Allows Unauthenticated Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76751"
    },
    {
      "rank": 425,
      "cve_id": "CVE-2026-76752",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "ClearPass Policy Manager (CPPM)",
      "cwe": null,
      "title": "Authentication Bypass Vulnerabilities in HPE Networking ClearPass Policy Manager Allow Unauthorized Administrative Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76752"
    },
    {
      "rank": 426,
      "cve_id": "CVE-2026-76753",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "ClearPass Policy Manager (CPPM)",
      "cwe": null,
      "title": "Unauthenticated Format String Vulnerability in HPE Networking ClearPass Policy Manager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76753"
    },
    {
      "rank": 427,
      "cve_id": "CVE-2026-76754",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "ClearPass Policy Manager (CPPM)",
      "cwe": null,
      "title": "Unauthenticated SQL Injection Vulnerability leads to Remote Code Execution in ClearPass Policy Manager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76754"
    },
    {
      "rank": 428,
      "cve_id": "CVE-2026-79796",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "ClearPass Policy Manager (CPPM)",
      "cwe": null,
      "title": "Authentication Bypass Vulnerabilities in ClearPass Policy Manager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79796"
    },
    {
      "rank": 429,
      "cve_id": "CVE-2026-79801",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "ClearPass Policy Manager (CPPM)",
      "cwe": null,
      "title": "Unauthenticated Missing Integrity Verification allows Remote Code Execution in ClearPass Policy Manager Client Agent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79801"
    },
    {
      "rank": 430,
      "cve_id": "CVE-2026-79805",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "ClearPass Policy Manager (CPPM)",
      "cwe": null,
      "title": "Authenticated Path Traversal Vulnerability Leads to Unauthorized File Access and Modification in ClearPass Policy Manager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79805"
    },
    {
      "rank": 431,
      "cve_id": "CVE-2026-104334",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-94",
      "title": "Langflow OSS is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104334"
    },
    {
      "rank": 432,
      "cve_id": "CVE-2026-105845",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "payloadcms",
      "product": "payload",
      "cwe": "CWE-89",
      "title": "Payload: SQL Injection in SQLite and Postgres",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105845"
    },
    {
      "rank": 433,
      "cve_id": "CVE-2026-105859",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "payloadcms",
      "product": "payload",
      "cwe": "CWE-639",
      "title": "Payload: Unauthorized update to collection documents",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105859"
    },
    {
      "rank": 434,
      "cve_id": "CVE-2026-106446",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "handlebars-lang",
      "product": "handlebars.js",
      "cwe": "CWE-94",
      "title": "Handlebars: JavaScript Injection via AST Type Confusion in compile (Program.blockParams)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106446"
    },
    {
      "rank": 435,
      "cve_id": "CVE-2026-67273",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Container Storage Modules",
      "cwe": "CWE-1336",
      "title": "Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Improper Neutralization of Special Elements Used in a Template Engine vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67273"
    },
    {
      "rank": 436,
      "cve_id": "CVE-2026-76745",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "AOS-Switch (AOS-S)",
      "cwe": null,
      "title": "Unauthenticated Adjacent Memory Corruption Vulnerabilities Leading to Remote Code Execution in AOS-S",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76745"
    },
    {
      "rank": 437,
      "cve_id": "CVE-2026-86360",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "System Update",
      "cwe": "CWE-22",
      "title": "Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker. This vulnerability is considered critical because it can be leveraged by an unauthenticated attacker to execute arbitrary code with root privileges. Successful exploitation may allow complete compromise of the vulnerable application and underlying operating system. Dell recommends customers upgrade at the earliest opportunity.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86360"
    },
    {
      "rank": 438,
      "cve_id": "CVE-2026-91140",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software",
      "product": "Autonomous REST Connector GenAI Agents",
      "cwe": "CWE-78",
      "title": "OS command injection in Progress Software Autonomous REST Connector GenAI Agents",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91140"
    },
    {
      "rank": 439,
      "cve_id": "CVE-2026-102322",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect Authorization in SiteIsolation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102322"
    },
    {
      "rank": 440,
      "cve_id": "CVE-2026-106197",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106197"
    },
    {
      "rank": 441,
      "cve_id": "CVE-2026-106211",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in TabStrip in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106211"
    },
    {
      "rank": 442,
      "cve_id": "CVE-2026-106227",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Core in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106227"
    },
    {
      "rank": 443,
      "cve_id": "CVE-2026-106234",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Network in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106234"
    },
    {
      "rank": 444,
      "cve_id": "CVE-2026-106239",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-190",
      "title": "Integer overflow in WebGL in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106239"
    },
    {
      "rank": 445,
      "cve_id": "CVE-2026-106241",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in Search in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106241"
    },
    {
      "rank": 446,
      "cve_id": "CVE-2026-106281",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Tint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106281"
    },
    {
      "rank": 447,
      "cve_id": "CVE-2026-106298",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Chrome Tabs in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106298"
    },
    {
      "rank": 448,
      "cve_id": "CVE-2026-106323",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in Chrome for iOS in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106323"
    },
    {
      "rank": 449,
      "cve_id": "CVE-2026-106329",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in FileSystem in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106329"
    },
    {
      "rank": 450,
      "cve_id": "CVE-2026-106358",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Navigation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106358"
    },
    {
      "rank": 451,
      "cve_id": "CVE-2026-106372",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in UI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106372"
    },
    {
      "rank": 452,
      "cve_id": "CVE-2026-106375",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-459",
      "title": "Incomplete cleanup in Dawn in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106375"
    },
    {
      "rank": 453,
      "cve_id": "CVE-2026-106382",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Chromecast in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106382"
    },
    {
      "rank": 454,
      "cve_id": "CVE-2026-106401",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-787",
      "title": "Out of bounds write in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106401"
    },
    {
      "rank": 455,
      "cve_id": "CVE-2026-106414",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106414"
    },
    {
      "rank": 456,
      "cve_id": "CVE-2026-106417",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-190",
      "title": "Integer overflow in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106417"
    },
    {
      "rank": 457,
      "cve_id": "CVE-2026-106419",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in ANGLE in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106419"
    },
    {
      "rank": 458,
      "cve_id": "CVE-2026-106501",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "backstage",
      "product": "backstage",
      "cwe": "CWE-200",
      "title": "Backstage: Sensitive information exposure in Scaffolder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106501"
    },
    {
      "rank": 459,
      "cve_id": "CVE-2026-102162",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "Wi-Fi Access Points",
      "cwe": "CWE-121",
      "title": "Security Advisory 0193",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102162"
    },
    {
      "rank": 460,
      "cve_id": "CVE-2026-76746",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "AOS-Switch (AOS-S)",
      "cwe": null,
      "title": "Unauthenticated Adjacent Buffer Overflow Vulnerability Leading to Information Disclosure in AOS-S",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76746"
    },
    {
      "rank": 461,
      "cve_id": "CVE-2026-101157",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "CloudVision CUE",
      "cwe": "CWE-79",
      "title": "Security Advisory 0192",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101157"
    },
    {
      "rank": 462,
      "cve_id": "CVE-2026-101158",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "CloudVision Portal",
      "cwe": "CWE-79",
      "title": "Security Advisory 0185",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101158"
    },
    {
      "rank": 463,
      "cve_id": "CVE-2026-102159",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "CloudVision CUE",
      "cwe": "CWE-306",
      "title": "Security Advisory 0190",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102159"
    },
    {
      "rank": 464,
      "cve_id": "CVE-2026-104070",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SPIP",
      "product": "SPIP Crayons Plugin",
      "cwe": "CWE-862",
      "title": "SPIP Crayons Plugin < 3.5.0 Authorization Bypass RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104070"
    },
    {
      "rank": 465,
      "cve_id": "CVE-2026-105844",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "payloadcms",
      "product": "payload",
      "cwe": "CWE-1321",
      "title": "Payload: Prototype pollution in Payload Import Export plugin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105844"
    },
    {
      "rank": 466,
      "cve_id": "CVE-2026-105851",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "payloadcms",
      "product": "payload",
      "cwe": "CWE-284",
      "title": "Payload: Field access control bypass on auth collections",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105851"
    },
    {
      "rank": 467,
      "cve_id": "CVE-2026-106037",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kvcache-ai",
      "product": "Mooncake",
      "cwe": "CWE-306",
      "title": "Mooncake through 0.3.13.post1 Missing Authentication in Store REST Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106037"
    },
    {
      "rank": 468,
      "cve_id": "CVE-2026-82531",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "smarty-php",
      "product": "smarty",
      "cwe": "CWE-94",
      "title": "Smarty before 4.5.8 and 5.x before 5.8.5 PHP Code Injection via extends: Inheritance Cache",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82531"
    },
    {
      "rank": 469,
      "cve_id": "CVE-2026-105863",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "payloadcms",
      "product": "payload",
      "cwe": "CWE-290",
      "title": "Payload authentication token field handling issue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105863"
    },
    {
      "rank": 470,
      "cve_id": "CVE-2026-106445",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "handlebars-lang",
      "product": "handlebars.js",
      "cwe": "CWE-184",
      "title": "Handlebars: JavaScript Injection via Own Property Check Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106445"
    },
    {
      "rank": 471,
      "cve_id": "CVE-2026-76747",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "AOS-Switch (AOS-S)",
      "cwe": null,
      "title": "Unauthenticated Buffer Overflow Vulnerabilities lead to Information Disclosure in AOS-S",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76747"
    },
    {
      "rank": 472,
      "cve_id": "CVE-2026-77178",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-787",
      "title": "Oracle VM VirtualBox before 7.2.8 allows guest OS users to cause an out-of-bounds write in the host OS in pcnetReceiveNoSync in DevPCNet.cpp in the PCNet (Am79C970A) network device model.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77178"
    },
    {
      "rank": 473,
      "cve_id": "CVE-2026-79794",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "ClearPass Policy Manager (CPPM)",
      "cwe": null,
      "title": "Authenticated SQL Injection Vulnerability in ClearPass Policy Manager Web-based Management Interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79794"
    },
    {
      "rank": 474,
      "cve_id": "CVE-2026-105793",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "microsoft",
      "product": "UFO",
      "cwe": "CWE-78",
      "title": "Microsoft UFO: Authenticated Android shell command injection in Mobile MCP `press_key`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105793"
    },
    {
      "rank": 475,
      "cve_id": "CVE-2026-105794",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "microsoft",
      "product": "msquic",
      "cwe": "CWE-295",
      "title": "MsQuic: Improper Certificate Validation in Microsoft.Native.Quic.MsQuic.OpenSSL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105794"
    },
    {
      "rank": 476,
      "cve_id": "CVE-2026-105835",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "planka",
      "product": "planka",
      "cwe": "CWE-307",
      "title": "PLANKA 2.2.0 through 2.2.1 TOTP Brute Force via verify-totp Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105835"
    },
    {
      "rank": 477,
      "cve_id": "CVE-2026-102167",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "Wi-Fi Access Points",
      "cwe": "CWE-121",
      "title": "Security Advisory 0197",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102167"
    },
    {
      "rank": 478,
      "cve_id": "CVE-2026-106448",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "StableLib",
      "product": "stablelib",
      "cwe": "CWE-1321",
      "title": "StableLib: Prototype poisoning via `__proto__` map keys in CBOR decoding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106448"
    },
    {
      "rank": 479,
      "cve_id": "CVE-2026-76748",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "AOS-Switch (AOS-S)",
      "cwe": null,
      "title": "Authenticated Privilege Escalation Vulnerability in the API of AOS-S",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76748"
    },
    {
      "rank": 480,
      "cve_id": "CVE-2026-79797",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "ClearPass Policy Manager (CPPM)",
      "cwe": null,
      "title": "Improper Access Control in HPE Networking ClearPass Android Client Application",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79797"
    },
    {
      "rank": 481,
      "cve_id": "CVE-2026-79799",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "ClearPass Policy Manager (CPPM)",
      "cwe": null,
      "title": "Unauthenticated Stored Cross-Site Scripting (XSS) Vulnerability in ClearPass Policy Manager Web-Based Management Interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79799"
    },
    {
      "rank": 482,
      "cve_id": "CVE-2026-79800",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "ClearPass Policy Manager (CPPM)",
      "cwe": null,
      "title": "Authenticated Path Traversal Vulnerability Leads to Remote Code Execution in ClearPass Policy Manager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79800"
    },
    {
      "rank": 483,
      "cve_id": "CVE-2026-79802",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "ClearPass Policy Manager (CPPM)",
      "cwe": null,
      "title": "Command Injection Vulnerability in the ClearPass Policy Manager Client Software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79802"
    },
    {
      "rank": 484,
      "cve_id": "CVE-2026-79803",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "ClearPass Policy Manager (CPPM)",
      "cwe": null,
      "title": "Authenticated Command Injection Leading to Privilege Escalation in ClearPass Policy Manager API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79803"
    },
    {
      "rank": 485,
      "cve_id": "CVE-2026-85523",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Felisify Information Technologies Industry and Trade Inc.",
      "product": "SambaBox",
      "cwe": "CWE-78",
      "title": "OS Command Injection in Felisify Informatics' SambaBox",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85523"
    },
    {
      "rank": 486,
      "cve_id": "CVE-2026-97655",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-94",
      "title": "Langflow OSS is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97655"
    },
    {
      "rank": 487,
      "cve_id": "CVE-2026-97676",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-94",
      "title": "Langflow OSS is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97676"
    },
    {
      "rank": 488,
      "cve_id": "CVE-2026-97678",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-693",
      "title": "Langflow OSS is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97678"
    },
    {
      "rank": 489,
      "cve_id": "CVE-2026-97679",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-94",
      "title": "Langflow OSS is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97679"
    },
    {
      "rank": 490,
      "cve_id": "CVE-2026-101207",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "OpenManage Integration",
      "cwe": "CWE-78",
      "title": "Dell OpenManage Integration with Microsoft Windows Admin Center, versions prior to 3.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101207"
    },
    {
      "rank": 491,
      "cve_id": "CVE-2026-102406",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-639",
      "title": "Authorization Bypass Through User-Controlled Key in Kibana Leading to Cross-Tenant Data Interception",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102406"
    },
    {
      "rank": 492,
      "cve_id": "CVE-2026-104335",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-284",
      "title": "Langflow OSS is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104335"
    },
    {
      "rank": 493,
      "cve_id": "CVE-2026-105788",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "microsoft",
      "product": "UFO",
      "cwe": "CWE-78",
      "title": "Microsoft UFO: Authenticated Android shell command injection in Mobile MCP type_text and launch_app",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105788"
    },
    {
      "rank": 494,
      "cve_id": "CVE-2026-105796",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "microsoft",
      "product": "kiota",
      "cwe": "CWE-94",
      "title": "Kiota: Code injection through doc-comment delimiter reformation in Kiota Java and PHP generators",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105796"
    },
    {
      "rank": 495,
      "cve_id": "CVE-2026-105797",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "microsoft",
      "product": "simplechat",
      "cwe": "CWE-78",
      "title": "SimpleChat: Command injection via authorization-gate ordering flaw (arbitrary process spawn through MCP stdio transport)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105797"
    },
    {
      "rank": 496,
      "cve_id": "CVE-2026-105812",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aws",
      "product": "bedrock-agentcore-starter-toolkit",
      "cwe": "CWE-94",
      "title": "Code injection via unencoded configuration values during Python code generation in Bedrock AgentCore Starter Toolkit agent import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105812"
    },
    {
      "rank": 497,
      "cve_id": "CVE-2026-105850",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "payloadcms",
      "product": "payload",
      "cwe": "CWE-837",
      "title": "Payload: Order confirmation validation issue in Payload Ecommerce",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105850"
    },
    {
      "rank": 498,
      "cve_id": "CVE-2026-106038",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kvcache-ai",
      "product": "Mooncake",
      "cwe": "CWE-306",
      "title": "Mooncake Store through 0.3.13.post1 Unauthenticated Object Deletion via Remove RPCs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106038"
    },
    {
      "rank": 499,
      "cve_id": "CVE-2026-106040",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kvcache-ai",
      "product": "Mooncake",
      "cwe": "CWE-862",
      "title": "Mooncake Store through 0.3.13.post1 Missing Authorization via EvictDiskReplica RPC",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106040"
    },
    {
      "rank": 500,
      "cve_id": "CVE-2026-106190",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106190"
    },
    {
      "rank": 501,
      "cve_id": "CVE-2026-106193",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Parser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106193"
    },
    {
      "rank": 502,
      "cve_id": "CVE-2026-106200",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Track in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106200"
    },
    {
      "rank": 503,
      "cve_id": "CVE-2026-106201",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-362",
      "title": "Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106201"
    },
    {
      "rank": 504,
      "cve_id": "CVE-2026-106203",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-459",
      "title": "Incomplete cleanup in Autofill in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106203"
    },
    {
      "rank": 505,
      "cve_id": "CVE-2026-106204",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106204"
    },
    {
      "rank": 506,
      "cve_id": "CVE-2026-106207",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-367",
      "title": "Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106207"
    },
    {
      "rank": 507,
      "cve_id": "CVE-2026-106212",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106212"
    },
    {
      "rank": 508,
      "cve_id": "CVE-2026-106218",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "TeamCity",
      "cwe": "CWE-184",
      "title": "In JetBrains TeamCity before 2026.1.3 2025.11.7 kotlin DSL sandbox escape leading to RCE on the server was possible",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106218"
    },
    {
      "rank": 509,
      "cve_id": "CVE-2026-106220",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Information leak in Passwords in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106220"
    },
    {
      "rank": 510,
      "cve_id": "CVE-2026-106225",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106225"
    },
    {
      "rank": 511,
      "cve_id": "CVE-2026-106235",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106235"
    },
    {
      "rank": 512,
      "cve_id": "CVE-2026-106240",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "title": "Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106240"
    },
    {
      "rank": 513,
      "cve_id": "CVE-2026-106248",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Bindings in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106248"
    },
    {
      "rank": 514,
      "cve_id": "CVE-2026-106249",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in Autofill in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106249"
    },
    {
      "rank": 515,
      "cve_id": "CVE-2026-106252",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-697",
      "title": "Incorrect comparison in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106252"
    },
    {
      "rank": 516,
      "cve_id": "CVE-2026-106255",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-362",
      "title": "Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106255"
    },
    {
      "rank": 517,
      "cve_id": "CVE-2026-106256",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Information leak in Passwords in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106256"
    },
    {
      "rank": 518,
      "cve_id": "CVE-2026-106257",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in HTML in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106257"
    },
    {
      "rank": 519,
      "cve_id": "CVE-2026-106268",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebRTC in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106268"
    },
    {
      "rank": 520,
      "cve_id": "CVE-2026-106269",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in CSS in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106269"
    },
    {
      "rank": 521,
      "cve_id": "CVE-2026-106274",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-706",
      "title": "Incorrect reference resolution in Browser in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106274"
    },
    {
      "rank": 522,
      "cve_id": "CVE-2026-106278",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Select in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106278"
    },
    {
      "rank": 523,
      "cve_id": "CVE-2026-106283",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Streaming in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106283"
    },
    {
      "rank": 524,
      "cve_id": "CVE-2026-106291",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in GarbageCollection in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106291"
    },
    {
      "rank": 525,
      "cve_id": "CVE-2026-106308",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-706",
      "title": "Incorrect reference resolution in Autofill in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106308"
    },
    {
      "rank": 526,
      "cve_id": "CVE-2026-106309",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in Selection in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106309"
    },
    {
      "rank": 527,
      "cve_id": "CVE-2026-106314",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in Bluetooth in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106314"
    },
    {
      "rank": 528,
      "cve_id": "CVE-2026-106315",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Modularization in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106315"
    },
    {
      "rank": 529,
      "cve_id": "CVE-2026-106318",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106318"
    },
    {
      "rank": 530,
      "cve_id": "CVE-2026-106334",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Information leak in Payments in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106334"
    },
    {
      "rank": 531,
      "cve_id": "CVE-2026-106335",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106335"
    },
    {
      "rank": 532,
      "cve_id": "CVE-2026-106341",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "title": "Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106341"
    },
    {
      "rank": 533,
      "cve_id": "CVE-2026-106342",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Information leak in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106342"
    },
    {
      "rank": 534,
      "cve_id": "CVE-2026-106346",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-754",
      "title": "Improper state validation in DevTools in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106346"
    },
    {
      "rank": 535,
      "cve_id": "CVE-2026-106347",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Track in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106347"
    },
    {
      "rank": 536,
      "cve_id": "CVE-2026-106349",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106349"
    },
    {
      "rank": 537,
      "cve_id": "CVE-2026-106350",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106350"
    },
    {
      "rank": 538,
      "cve_id": "CVE-2026-106352",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in WebProtect in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106352"
    },
    {
      "rank": 539,
      "cve_id": "CVE-2026-106357",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebRTC in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106357"
    },
    {
      "rank": 540,
      "cve_id": "CVE-2026-106371",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in Transactions Platform in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106371"
    },
    {
      "rank": 541,
      "cve_id": "CVE-2026-106373",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Fonts in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106373"
    },
    {
      "rank": 542,
      "cve_id": "CVE-2026-106374",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "title": "Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106374"
    },
    {
      "rank": 543,
      "cve_id": "CVE-2026-106383",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106383"
    },
    {
      "rank": 544,
      "cve_id": "CVE-2026-106387",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106387"
    },
    {
      "rank": 545,
      "cve_id": "CVE-2026-106411",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Parser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106411"
    },
    {
      "rank": 546,
      "cve_id": "CVE-2026-106421",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106421"
    },
    {
      "rank": 547,
      "cve_id": "CVE-2026-106423",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106423"
    },
    {
      "rank": 548,
      "cve_id": "CVE-2026-106443",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kozea",
      "product": "WeasyPrint",
      "cwe": "CWE-20",
      "title": "WeasyPrint: EPS images reach the Ghostscript interpreter resulting in RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106443"
    },
    {
      "rank": 549,
      "cve_id": "CVE-2026-96890",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitHub",
      "product": "Enterprise Server",
      "cwe": "CWE-918",
      "title": "Server-Side Request Forgery vulnerability was identified in GitHub Enterprise Server that allowed requests to attacker-controlled internal hosts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96890"
    },
    {
      "rank": 550,
      "cve_id": "CVE-2026-102161",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "CloudVision CUE",
      "cwe": "CWE-290",
      "title": "Security Advisory 0190",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102161"
    },
    {
      "rank": 551,
      "cve_id": "CVE-2026-102163",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "Wi-Fi Access Points",
      "cwe": "CWE-787",
      "title": "Security Advisory 0195",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102163"
    },
    {
      "rank": 552,
      "cve_id": "CVE-2026-105798",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "microsoft",
      "product": "simplechat",
      "cwe": "CWE-79",
      "title": "SimpleChat: Stored XSS via group document filename in inline onclick handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105798"
    },
    {
      "rank": 553,
      "cve_id": "CVE-2026-105854",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "payloadcms",
      "product": "payload",
      "cwe": "CWE-400",
      "title": "Payload: ReDoS in Multipart Content-Type Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105854"
    },
    {
      "rank": 554,
      "cve_id": "CVE-2026-105862",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "payloadcms",
      "product": "payload",
      "cwe": "CWE-79",
      "title": "Payload: Bypassed sanitization of user uploaded SVGs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105862"
    },
    {
      "rank": 555,
      "cve_id": "CVE-2026-105985",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craftcms",
      "product": "cms",
      "cwe": "CWE-1336",
      "title": "Authenticated RCE via render-components Entry Type overrides",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105985"
    },
    {
      "rank": 556,
      "cve_id": "CVE-2026-106104",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "quasarframework",
      "product": "quasar",
      "cwe": "CWE-1333",
      "title": "Quasar Framework: Super-linear regex backtracking on User-Agent lets one request stall a Quasar SSR server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106104"
    },
    {
      "rank": 557,
      "cve_id": "CVE-2026-106447",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "StableLib",
      "product": "stablelib",
      "cwe": "CWE-674",
      "title": "StableLib: Stack exhaustion denial of service via deeply nested CBOR arrays, maps, or tags",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106447"
    },
    {
      "rank": 558,
      "cve_id": "CVE-2026-101154",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "CloudVision Portal",
      "cwe": "CWE-22",
      "title": "Security Advisory 0189",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101154"
    },
    {
      "rank": 559,
      "cve_id": "CVE-2026-101155",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "CloudVision Portal",
      "cwe": "CWE-22",
      "title": "Security Advisory 0189",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101155"
    },
    {
      "rank": 560,
      "cve_id": "CVE-2026-102160",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "CloudVision CUE",
      "cwe": "CWE-78",
      "title": "Security Advisory 0190",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102160"
    },
    {
      "rank": 561,
      "cve_id": "CVE-2026-104069",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "danielbrendel",
      "product": "hortusfox-web",
      "cwe": "CWE-434",
      "title": "HortusFox < 6.2 Remote Code Execution via Theme Import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104069"
    },
    {
      "rank": 562,
      "cve_id": "CVE-2026-105806",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "payloadcms",
      "product": "payload",
      "cwe": "CWE-862",
      "title": "Payload: Improper access control for MCP API keys",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105806"
    },
    {
      "rank": 563,
      "cve_id": "CVE-2026-105856",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "payloadcms",
      "product": "payload",
      "cwe": "CWE-89",
      "title": "Payload: SQL injection in SQLite/Postgres",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105856"
    },
    {
      "rank": 564,
      "cve_id": "CVE-2026-105868",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "payloadcms",
      "product": "payload",
      "cwe": "CWE-434",
      "title": "Payload: Uploaded XML files could execute same-origin JavaScript",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105868"
    },
    {
      "rank": 565,
      "cve_id": "CVE-2026-106186",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-427",
      "title": "Uncontrolled search path element in CredentialProvider in Google Chrome on on Windows prior to 155.0.8059.39 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106186"
    },
    {
      "rank": 566,
      "cve_id": "CVE-2026-105837",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sezero",
      "product": "libmikmod",
      "cwe": "CWE-190",
      "title": "libmikmod before 3.3.14 Heap Buffer Overflow via DSM Loader Integer Overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105837"
    },
    {
      "rank": 567,
      "cve_id": "CVE-2026-105839",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sezero",
      "product": "libmikmod",
      "cwe": "CWE-190",
      "title": "libmikmod before 3.3.14 Heap Buffer Overflow via OKT Loader OKT_doPBOD",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105839"
    },
    {
      "rank": 568,
      "cve_id": "CVE-2026-106439",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hydra-ecosystem",
      "product": "hydra",
      "cwe": "CWE-470",
      "title": "Hydra: Mutable instantiate policy sets allow target blocklist bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106439"
    },
    {
      "rank": 569,
      "cve_id": "CVE-2026-106459",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "backstage",
      "product": "backstage",
      "cwe": "CWE-200",
      "title": "Backstage: Improper input validation in Sentry scaffolder actions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106459"
    },
    {
      "rank": 570,
      "cve_id": "CVE-2026-106486",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "backstage",
      "product": "backstage",
      "cwe": "CWE-22",
      "title": "Backstage: Improper filesystem validation in Bitbucket pull-request scaffolder actions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106486"
    },
    {
      "rank": 571,
      "cve_id": "CVE-2026-106500",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "backstage",
      "product": "backstage",
      "cwe": "CWE-59",
      "title": "Backstage: Improper task state validation in Scaffolder backend",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106500"
    },
    {
      "rank": 572,
      "cve_id": "CVE-2026-106547",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The HDF Group",
      "product": "HDF5",
      "cwe": "CWE-122",
      "title": "HDF5 heap buffer overflow in H5VM_array_fill via crafted fill-value metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106547"
    },
    {
      "rank": 573,
      "cve_id": "CVE-2026-105801",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openapi-generators",
      "product": "openapi-python-client",
      "cwe": "CWE-94",
      "title": "openapi-python-client: Malicious OpenAPI Documents can cause Arbitrary Code Generation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105801"
    },
    {
      "rank": 574,
      "cve_id": "CVE-2026-106105",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "quasarframework",
      "product": "quasar",
      "cwe": "CWE-732",
      "title": "Quasar Framework: Development TLS private keys are cached with overly permissive filesystem permissions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106105"
    },
    {
      "rank": 575,
      "cve_id": "CVE-2026-106512",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "sachertortephp",
      "cwe": "CWE-20",
      "title": "MISP sachertortephp - CakeResponse::download() HTTP Response Splitting via Unsanitized Filename Enables Stored XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106512"
    },
    {
      "rank": 576,
      "cve_id": "CVE-2026-97680",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-284",
      "title": "Langflow OSS is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97680"
    },
    {
      "rank": 577,
      "cve_id": "CVE-2026-106107",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "quasarframework",
      "product": "quasar",
      "cwe": "CWE-79",
      "title": "Quasar Framework: App Vite SSR and SSG nonce attributes are not safely constrained",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106107"
    },
    {
      "rank": 578,
      "cve_id": "CVE-2026-106191",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in Actor in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106191"
    },
    {
      "rank": 579,
      "cve_id": "CVE-2026-106194",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in WebAppInstalls in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106194"
    },
    {
      "rank": 580,
      "cve_id": "CVE-2026-106228",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-441",
      "title": "Confused deputy in Google Lens in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106228"
    },
    {
      "rank": 581,
      "cve_id": "CVE-2026-106233",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Metrics in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106233"
    },
    {
      "rank": 582,
      "cve_id": "CVE-2026-106238",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-362",
      "title": "Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106238"
    },
    {
      "rank": 583,
      "cve_id": "CVE-2026-106247",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-122",
      "title": "Buffer overflow in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106247"
    },
    {
      "rank": 584,
      "cve_id": "CVE-2026-106292",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-122",
      "title": "Buffer overflow in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106292"
    },
    {
      "rank": 585,
      "cve_id": "CVE-2026-106293",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "title": "Type confusion in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106293"
    },
    {
      "rank": 586,
      "cve_id": "CVE-2026-106377",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-362",
      "title": "Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106377"
    },
    {
      "rank": 587,
      "cve_id": "CVE-2026-106378",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-250",
      "title": "Privilege elevation in Sandbox in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106378"
    },
    {
      "rank": 588,
      "cve_id": "CVE-2026-106393",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Storage in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106393"
    },
    {
      "rank": 589,
      "cve_id": "CVE-2026-106409",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-706",
      "title": "Incorrect reference resolution in WebAppInstalls in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106409"
    },
    {
      "rank": 590,
      "cve_id": "CVE-2026-106412",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-367",
      "title": "Race condition in Core in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106412"
    },
    {
      "rank": 591,
      "cve_id": "CVE-2026-106426",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-362",
      "title": "Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106426"
    },
    {
      "rank": 592,
      "cve_id": "CVE-2026-67270",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Container Storage Modules (CSM)",
      "cwe": "CWE-295",
      "title": "Dell Container Storage Modules (CSM) versions prior to 1.18.0, contains an Improper Certificate Validation vulnerability in the proxy-server component. An unauthenticated adjacent network attacker could potentially exploit this vulnerability, leading to information exposure of storage backend administrator credentials.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67270"
    },
    {
      "rank": 593,
      "cve_id": "CVE-2026-86361",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "System Update",
      "cwe": "CWE-732",
      "title": "Dell System Update, versions prior to 2.3.0.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86361"
    },
    {
      "rank": 594,
      "cve_id": "CVE-2026-86362",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "System Update",
      "cwe": "CWE-284",
      "title": "Dell System Update, versions prior to 2.3.0.0, contains an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86362"
    },
    {
      "rank": 595,
      "cve_id": "CVE-2026-94114",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Commons BCEL",
      "cwe": "CWE-386",
      "title": "Apache Commons BCEL: Nested Code/Record attributes drive unbounded parse-time recursion in ClassParser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94114"
    },
    {
      "rank": 596,
      "cve_id": "CVE-2026-97674",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-94",
      "title": "Langflow OSS is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97674"
    },
    {
      "rank": 597,
      "cve_id": "CVE-2026-103360",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-22",
      "title": "Langflow OSS is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103360"
    },
    {
      "rank": 598,
      "cve_id": "CVE-2026-105858",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "payloadcms",
      "product": "payload",
      "cwe": "CWE-94",
      "title": "Payload: Remote Code Execution through first-register",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105858"
    },
    {
      "rank": 599,
      "cve_id": "CVE-2026-105865",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "payloadcms",
      "product": "payload",
      "cwe": "CWE-22",
      "title": "Payload: Incomplete validation during the upload file lifecycle",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105865"
    },
    {
      "rank": 600,
      "cve_id": "CVE-2026-106488",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "backstage",
      "product": "backstage",
      "cwe": "CWE-287",
      "title": "Backstage: Improper authentication in the OIDC provider",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106488"
    },
    {
      "rank": 601,
      "cve_id": "CVE-2026-106503",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "backstage",
      "product": "backstage",
      "cwe": "CWE-178",
      "title": "Backstage: Scaffolder action input authorization bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106503"
    },
    {
      "rank": 602,
      "cve_id": "CVE-2026-65142",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Model-Optimizer",
      "cwe": "CWE-502",
      "title": "NVIDIA Model-Optimizer contains a vulnerability where an attacker may cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65142"
    },
    {
      "rank": 603,
      "cve_id": "CVE-2026-79806",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "ClearPass Policy Manager (CPPM)",
      "cwe": null,
      "title": "Authenticated Local Privilege Escalation in ClearPass Policy Manager OnGuard Linux Agent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79806"
    },
    {
      "rank": 604,
      "cve_id": "CVE-2026-79807",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "ClearPass Policy Manager (CPPM)",
      "cwe": null,
      "title": "Authenticated Local Missing Integrity Verification Vulnerability leads to Local Privilege Escalation in the ClearPass Policy Manager Windows Client Software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79807"
    },
    {
      "rank": 605,
      "cve_id": "CVE-2026-79808",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "ClearPass Policy Manager (CPPM)",
      "cwe": null,
      "title": "Local Authenticated Buffer Overflow Vulnerability in the ClearPass Policy Manager OnGuard Agent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79808"
    },
    {
      "rank": 606,
      "cve_id": "CVE-2026-101258",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-787",
      "title": "Ghostscript: ghostscript: -dsafer sandbox bypass via type 5 shading oob write and procedure-stream use-after-free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101258"
    },
    {
      "rank": 607,
      "cve_id": "CVE-2026-106062",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-119",
      "title": "Gimp: gimp: heap buffer overflow in dds loader on crafted directdraw surface file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106062"
    },
    {
      "rank": 608,
      "cve_id": "CVE-2026-106440",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hydra-ecosystem",
      "product": "hydra",
      "cwe": "CWE-470",
      "title": "Hydra: Optuna custom_search_space can resolve and execute untrusted callables via get_method",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106440"
    },
    {
      "rank": 609,
      "cve_id": "CVE-2026-106441",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hydra-ecosystem",
      "product": "hydra",
      "cwe": "CWE-94",
      "title": "Hydra logging configuration permits unsafe callable resolution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106441"
    },
    {
      "rank": 610,
      "cve_id": "CVE-2026-106442",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hydra-ecosystem",
      "product": "hydra",
      "cwe": "CWE-184",
      "title": "Hydra instantiate target blacklist bypasses permit code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106442"
    },
    {
      "rank": 611,
      "cve_id": "CVE-2026-43598",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AMD",
      "product": "AMD Instinct™ MI210",
      "cwe": "CWE-822",
      "title": "Improper input validation in the AMD ROCm Communication Collectives Library (RCCL) could allow a compromised peer rank or network-adjacent attacker to dereference an attacker-controlled pointer, potentially resulting in remote code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43598"
    },
    {
      "rank": 612,
      "cve_id": "CVE-2026-61411",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Container Storage Modules",
      "cwe": "CWE-532",
      "title": "Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61411"
    },
    {
      "rank": 613,
      "cve_id": "CVE-2026-76105",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Container Storage Modules",
      "cwe": "CWE-330",
      "title": "Dell Container Storage Modules, versions prior to 1.18.0 contain(s) an Use of Insufficiently Random Values vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Information tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76105"
    },
    {
      "rank": 614,
      "cve_id": "CVE-2026-101027",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea",
      "cwe": null,
      "title": "Gitea migration SSRF through ALLOWED_DOMAINS address check bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101027"
    },
    {
      "rank": 615,
      "cve_id": "CVE-2026-101331",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-522",
      "title": "Langflow OSS is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101331"
    },
    {
      "rank": 616,
      "cve_id": "CVE-2026-102165",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "Wi-Fi Access Points",
      "cwe": "CWE-121",
      "title": "Security Advisory 0198",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102165"
    },
    {
      "rank": 617,
      "cve_id": "CVE-2026-105840",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Uwe Ohse",
      "product": "lrzsz",
      "cwe": "CWE-22",
      "title": "lrzsz before 0.13.0 Path Traversal via lrz Restricted Mode checkpath()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105840"
    },
    {
      "rank": 618,
      "cve_id": "CVE-2026-105841",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Uwe Ohse",
      "product": "lrzsz",
      "cwe": "CWE-78",
      "title": "lrzsz before 0.13.0 OS Command Injection via lrz Pipe Mode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105841"
    },
    {
      "rank": 619,
      "cve_id": "CVE-2026-105849",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "payloadcms",
      "product": "payload",
      "cwe": "CWE-201",
      "title": "Payload: API key disclosure through ordinary document reads",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105849"
    },
    {
      "rank": 620,
      "cve_id": "CVE-2026-106455",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "backstage",
      "product": "backstage",
      "cwe": "CWE-918",
      "title": "Backstage: Improper validation of MkDocs plugin configuration in TechDocs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106455"
    },
    {
      "rank": 621,
      "cve_id": "CVE-2026-106498",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "backstage",
      "product": "backstage",
      "cwe": "CWE-863",
      "title": "Backstage: Improper URL validation in catalog entity placeholder resolution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106498"
    },
    {
      "rank": 622,
      "cve_id": "CVE-2026-106505",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "backstage",
      "product": "backstage",
      "cwe": "CWE-426",
      "title": "Backstage: Bypass of MkDocs configuration sanitizer in TechDocs backend",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106505"
    },
    {
      "rank": 623,
      "cve_id": "CVE-2026-106509",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "backstage",
      "product": "backstage",
      "cwe": "CWE-94",
      "title": "Backstage: Improper validation of MkDocs theme configuration in TechDocs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106509"
    },
    {
      "rank": 624,
      "cve_id": "CVE-2026-63697",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "System Update",
      "cwe": "CWE-295",
      "title": "Dell System Update, versions prior to 2.3.0.0, contains an Improper Certificate Validation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63697"
    },
    {
      "rank": 625,
      "cve_id": "CVE-2026-101152",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "CloudVision Portal",
      "cwe": "CWE-601",
      "title": "Security Advisory 0187",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101152"
    },
    {
      "rank": 626,
      "cve_id": "CVE-2026-105855",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "payloadcms",
      "product": "payload",
      "cwe": "CWE-284",
      "title": "Payload: Field-level password update restrictions were not enforced",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105855"
    },
    {
      "rank": 627,
      "cve_id": "CVE-2026-106492",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "backstage",
      "product": "backstage",
      "cwe": "CWE-269",
      "title": "Backstage: Improper preservation of access restrictions during service credential delegation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106492"
    },
    {
      "rank": 628,
      "cve_id": "CVE-2026-95140",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-22",
      "title": "kkFileView v5.0.0 through v5.0.2 contains a directory traversal vulnerability in FileController.java. The fileUpload, createFolder and existsFile endpoints accept a \"path\" parameter that is concatenated into the upload base path without validation, allowing unauthenticated attackers to create arbitrary directories and write arbitrary files outside the intended fileDir root via a crafted multipart request",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95140"
    },
    {
      "rank": 629,
      "cve_id": "CVE-2026-103831",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TrueLayer",
      "product": "TrueLayer Magento 2 Plugin",
      "cwe": "CWE-502",
      "title": "Insecure deserialization in the TrueLayer Magento 2 plugin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103831"
    },
    {
      "rank": 630,
      "cve_id": "CVE-2026-104850",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "modelcontextprotocol",
      "product": "typescript-sdk",
      "cwe": "CWE-345",
      "title": "MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104850"
    },
    {
      "rank": 631,
      "cve_id": "CVE-2026-105791",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "microsoft",
      "product": "UFO",
      "cwe": "CWE-88",
      "title": "Microsoft UFO: Arbitrary code execution in `run_shell` via `explorer.exe` argument injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105791"
    },
    {
      "rank": 632,
      "cve_id": "CVE-2026-106110",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SixLabors",
      "product": "ImageSharp",
      "cwe": "CWE-787",
      "title": "ImageSharp: TIFF CCITT T4 encoder can write past its compressed output buffer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106110"
    },
    {
      "rank": 633,
      "cve_id": "CVE-2026-106112",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SixLabors",
      "product": "ImageSharp",
      "cwe": "CWE-787",
      "title": "ImageSharp: ICC LUT16 output channel count can write beyond Vector4",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106112"
    },
    {
      "rank": 634,
      "cve_id": "CVE-2026-106113",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SixLabors",
      "product": "ImageSharp",
      "cwe": "CWE-787",
      "title": "ImageSharp: HistogramEqualization uses an unvalidated luminance as an unchecked histogram index",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106113"
    },
    {
      "rank": 635,
      "cve_id": "CVE-2026-106115",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SixLabors",
      "product": "ImageSharp",
      "cwe": "CWE-787",
      "title": "ImageSharp: TIFF CCITT T6 encoder writes beyond an undersized output buffer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106115"
    },
    {
      "rank": 636,
      "cve_id": "CVE-2026-106117",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SixLabors",
      "product": "ImageSharp",
      "cwe": "CWE-787",
      "title": "ImageSharp: CCITT fax decompression (T4/Modified Huffman): unbounded WriteBits overflows strip buffer — heap OOB write in SixLabors.ImageSharp",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106117"
    },
    {
      "rank": 637,
      "cve_id": "CVE-2026-106118",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SixLabors",
      "product": "ImageSharp",
      "cwe": "CWE-787",
      "title": "ImageSharp: Tiled fax TIFF: tile buffer sized by TileWidth but fax decompressor writes scanlines of ImageWidth — heap OOB write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106118"
    },
    {
      "rank": 638,
      "cve_id": "CVE-2026-82162",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Command | Configure (DCC)",
      "cwe": "CWE-175",
      "title": "Dell Command | Configure (DCC), versions prior to 5.2.3.35, contain an Improper Handling of Mixed Encoding vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Elevation of Privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82162"
    },
    {
      "rank": 639,
      "cve_id": "CVE-2026-106279",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-706",
      "title": "Incorrect reference resolution in Passwords in Google Chrome on on iOS prior to 155.0.8059.39 allowed a local attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106279"
    },
    {
      "rank": 640,
      "cve_id": "CVE-2026-71168",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "System Update",
      "cwe": "CWE-22",
      "title": "Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Remote execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71168"
    },
    {
      "rank": 641,
      "cve_id": "CVE-2026-79809",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "ClearPass Policy Manager (CPPM)",
      "cwe": null,
      "title": "Unauthenticated Path Traversal in ClearPass Policy Manager API Endpoint Leads to Authorization Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79809"
    },
    {
      "rank": 642,
      "cve_id": "CVE-2026-106451",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yawkat",
      "product": "lz4-java",
      "cwe": "CWE-367",
      "title": "yawkat LZ4 Java: Native library extraction to a shared temporary directory is vulnerable to file replacement by another local user",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106451"
    },
    {
      "rank": 643,
      "cve_id": "CVE-2026-79810",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "ClearPass Policy Manager (CPPM)",
      "cwe": null,
      "title": "Authenticated Remote Code Execution Vulnerabilities in HPE Networking ClearPass Policy Manager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79810"
    },
    {
      "rank": 644,
      "cve_id": "CVE-2026-79811",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "ClearPass Policy Manager (CPPM)",
      "cwe": null,
      "title": "Authenticated SQL Injection allows Remote Code Execution in ClearPass Policy Manager API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79811"
    },
    {
      "rank": 645,
      "cve_id": "CVE-2026-101153",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "CloudVision Portal",
      "cwe": "CWE-22",
      "title": "Security Advisory 0188",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101153"
    },
    {
      "rank": 646,
      "cve_id": "CVE-2026-103007",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Elasticsearch",
      "cwe": "CWE-863",
      "title": "Incorrect Authorization in Elasticsearch Leading to Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103007"
    },
    {
      "rank": 647,
      "cve_id": "CVE-2026-105861",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "payloadcms",
      "product": "payload",
      "cwe": "CWE-200",
      "title": "Payload external upload trust validation issue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105861"
    },
    {
      "rank": 648,
      "cve_id": "CVE-2026-26287",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "external-secrets",
      "product": "external-secrets",
      "cwe": "CWE-696",
      "title": "External Secrets Operator: label enforcement bypass in webhook generator enables secret exfiltration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26287"
    },
    {
      "rank": 649,
      "cve_id": "CVE-2026-70411",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Container Storage Modules (CSM)",
      "cwe": "CWE-306",
      "title": "Dell Container Storage Modules (CSM), versions prior to 1.18.0, contains a Missing Authentication for Critical Function vulnerability in the csm-authorization-tenant gRPC service (TenantService). An unauthenticated adjacent network attacker could potentially exploit this vulnerability, leading to unauthorized creation of tenant entities, cross-tenant role injection, and modification of storage access control flags.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70411"
    },
    {
      "rank": 650,
      "cve_id": "CVE-2026-83550",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Multicluster Global Hub",
      "cwe": "CWE-489",
      "title": "Postgres-exporter: net/http/pprof exposed on metrics listener",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83550"
    },
    {
      "rank": 651,
      "cve_id": "CVE-2026-102155",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "CloudVision CUE",
      "cwe": "CWE-611",
      "title": "Security Advisory 0190",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102155"
    },
    {
      "rank": 652,
      "cve_id": "CVE-2026-102158",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "CloudVision CUE",
      "cwe": "CWE-74",
      "title": "Security Advisory 0190",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102158"
    },
    {
      "rank": 653,
      "cve_id": "CVE-2026-102168",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "Wi-Fi Access Points",
      "cwe": "CWE-191",
      "title": "Security Advisory 0194",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102168"
    },
    {
      "rank": 654,
      "cve_id": "CVE-2026-102169",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "Wi-Fi Access Points",
      "cwe": "CWE-476",
      "title": "Security Advisory 0194",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102169"
    },
    {
      "rank": 655,
      "cve_id": "CVE-2026-103009",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Elasticsearch",
      "cwe": "CWE-639",
      "title": "Authorization Bypass Through User-Controlled Key in Elasticsearch Leading to Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103009"
    },
    {
      "rank": 656,
      "cve_id": "CVE-2026-104944",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Tapo C500 v2.0",
      "cwe": "CWE-823",
      "title": "Unauthenticated TDP Function Pointer Dispatch Denial of Service in TP-Link Tapo C500",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104944"
    },
    {
      "rank": 657,
      "cve_id": "CVE-2026-105811",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aws",
      "product": "qnabot-on-aws",
      "cwe": "CWE-639",
      "title": "Authorization bypass through a user-controlled key in the Amazon Q Business Lambda hook sample in QnABot on AWS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105811"
    },
    {
      "rank": 658,
      "cve_id": "CVE-2026-105834",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rundeck",
      "product": "rundeck",
      "cwe": "CWE-22",
      "title": "Rundeck before 6.2.0 Arbitrary File Read via File Resource Model Source",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105834"
    },
    {
      "rank": 659,
      "cve_id": "CVE-2026-105847",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "payloadcms",
      "product": "payload",
      "cwe": "CWE-200",
      "title": "Payload: Polymorphic join queries could disclose hidden fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105847"
    },
    {
      "rank": 660,
      "cve_id": "CVE-2026-105853",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "payloadcms",
      "product": "payload",
      "cwe": "CWE-200",
      "title": "Payload: Token refresh and password reset responses may expose restricted user fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105853"
    },
    {
      "rank": 661,
      "cve_id": "CVE-2026-105860",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "payloadcms",
      "product": "payload",
      "cwe": "CWE-862",
      "title": "Payload: Tenant authorization bypass in Multi-Tenant Plugin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105860"
    },
    {
      "rank": 662,
      "cve_id": "CVE-2026-105867",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "payloadcms",
      "product": "payload",
      "cwe": "CWE-639",
      "title": "Payload: Client uploads could overwrite S3 objects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105867"
    },
    {
      "rank": 663,
      "cve_id": "CVE-2026-106100",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "payloadcms",
      "product": "payload",
      "cwe": "CWE-639",
      "title": "Payload: Field-level write access bypass in Payload on MongoDB",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106100"
    },
    {
      "rank": 664,
      "cve_id": "CVE-2026-106103",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "quasarframework",
      "product": "quasar",
      "cwe": "CWE-22",
      "title": "Quasar Framework: Path Traversal / Arbitrary File Write via crafted Icon Genie profile",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106103"
    },
    {
      "rank": 665,
      "cve_id": "CVE-2026-106106",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "quasarframework",
      "product": "quasar",
      "cwe": "CWE-79",
      "title": "Quasar Framework: SSR/SSG dev error page discloses the full shell environment and its </script> escape is bypassable",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106106"
    },
    {
      "rank": 666,
      "cve_id": "CVE-2026-56906",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-362",
      "title": "In ep_free of eventpoll.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56906"
    },
    {
      "rank": 667,
      "cve_id": "CVE-2026-84854",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wibu-systems-ag",
      "product": "wibukey",
      "cwe": "CWE-787",
      "title": "Out of Bound Write on WibuKey for Windows",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84854"
    },
    {
      "rank": 668,
      "cve_id": "CVE-2025-8352",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ESET spol. s.r.o",
      "product": "ESET PROTECT On-Prem",
      "cwe": "CWE-770",
      "title": "Denial-of-service vulnerability in ESET PROTECT On-Prem",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-8352"
    },
    {
      "rank": 669,
      "cve_id": "CVE-2026-66666",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Automattic",
      "product": "WordPress",
      "cwe": "CWE-201",
      "title": "WordPress Core <= 7.1.2 - Unauthenticated Sensitive Data Exposure of Comments on Private and Unpublished Posts via Comment Feed vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66666"
    },
    {
      "rank": 670,
      "cve_id": "CVE-2026-77050",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "djangoproject",
      "product": "Django",
      "cwe": "CWE-789",
      "title": "Potential denial-of-service vulnerability in get_supported_language_variant()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77050"
    },
    {
      "rank": 671,
      "cve_id": "CVE-2026-84429",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "djangoproject",
      "product": "Django",
      "cwe": "CWE-407",
      "title": "Potential denial-of-service vulnerability in HTTP header parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84429"
    },
    {
      "rank": 672,
      "cve_id": "CVE-2026-87890",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "djangoproject",
      "product": "Django",
      "cwe": "CWE-918",
      "title": "Potential request forgery via spatial lookup byte values",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87890"
    },
    {
      "rank": 673,
      "cve_id": "CVE-2026-102156",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "CloudVision CUE",
      "cwe": "CWE-74",
      "title": "Security Advisory 0191",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102156"
    },
    {
      "rank": 674,
      "cve_id": "CVE-2026-104073",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netbox-community",
      "product": "netbox",
      "cwe": "CWE-79",
      "title": "NetBox 2.9.5 < 4.7.0 Session Hijacking via Custom Links",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104073"
    },
    {
      "rank": 675,
      "cve_id": "CVE-2026-105805",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "payloadcms",
      "product": "payload",
      "cwe": "CWE-200",
      "title": "Payload: Sort queries could expose protected field information",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105805"
    },
    {
      "rank": 676,
      "cve_id": "CVE-2026-105852",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "payloadcms",
      "product": "payload",
      "cwe": "CWE-862",
      "title": "Payload relationship-query authorization bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105852"
    },
    {
      "rank": 677,
      "cve_id": "CVE-2026-105866",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "payloadcms",
      "product": "payload",
      "cwe": "CWE-307",
      "title": "Payload: Unauthenticated account-lockout denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105866"
    },
    {
      "rank": 678,
      "cve_id": "CVE-2026-106039",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kvcache-ai",
      "product": "Mooncake",
      "cwe": "CWE-862",
      "title": "Mooncake Store through 0.3.13.post1 Missing Authorization in Replication Task RPC",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106039"
    },
    {
      "rank": 679,
      "cve_id": "CVE-2026-106041",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kvcache-ai",
      "product": "Mooncake",
      "cwe": "CWE-862",
      "title": "Mooncake Store through 0.3.13.post1 Missing Authorization via NotifyOffloadSuccess RPC",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106041"
    },
    {
      "rank": 680,
      "cve_id": "CVE-2026-106513",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-284",
      "title": "MISP: Site-Admin Can Repoint Redis Workers to Attacker-Controlled Server via UI/API Configuration Change",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106513"
    },
    {
      "rank": 681,
      "cve_id": "CVE-2026-19029",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The HDF Group",
      "product": "HDF5",
      "cwe": "CWE-125",
      "title": "HDF5 scale-offset filter heap buffer over-read via crafted chunk",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19029"
    },
    {
      "rank": 682,
      "cve_id": "CVE-2026-56936",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-119",
      "title": "In wacom_hid_set_device_mode of wacom_sys.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56936"
    },
    {
      "rank": 683,
      "cve_id": "CVE-2026-104048",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-1025",
      "title": "Sssd: sssd: authorization bypass via cross-domain username collision in hbac evaluation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104048"
    },
    {
      "rank": 684,
      "cve_id": "CVE-2026-104945",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Tapo C500 v2.0",
      "cwe": "CWE-121",
      "title": "Authenticated ONVIF PTZ Out-of-Bounds Stack Write Denial of Service in TP-Link Tapo C500",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104945"
    },
    {
      "rank": 685,
      "cve_id": "CVE-2026-105485",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Devolutions",
      "product": "Server",
      "cwe": "CWE-294",
      "title": "Authentication bypass OAuth device authorization flow in Devolutions Server 2026.3.7.0 and earlier allows a remote attacker to take over a user's account via replay of a captured device verification link by an authenticated victim.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105485"
    },
    {
      "rank": 686,
      "cve_id": "CVE-2026-105838",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sezero",
      "product": "libmikmod",
      "cwe": "CWE-125",
      "title": "libmikmod before 3.3.14 Heap Out-of-Bounds Read via IT Module Loader",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105838"
    },
    {
      "rank": 687,
      "cve_id": "CVE-2026-106457",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "backstage",
      "product": "backstage",
      "cwe": "CWE-287",
      "title": "Backstage: Insufficient audience validation in the Cloudflare Access auth provider",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106457"
    },
    {
      "rank": 688,
      "cve_id": "CVE-2026-106460",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "backstage",
      "product": "backstage",
      "cwe": "CWE-287",
      "title": "Backstage: Explicit negative email verification can be ignored during shared OAuth profile normalization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106460"
    },
    {
      "rank": 689,
      "cve_id": "CVE-2026-56952",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-862",
      "title": "In platform_msg_handler_init of default_msg_handlers.c, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56952"
    },
    {
      "rank": 690,
      "cve_id": "CVE-2026-79813",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "ClearPass Policy Manager (CPPM)",
      "cwe": null,
      "title": "Local Privilege Escalation in ClearPass Client Software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79813"
    },
    {
      "rank": 691,
      "cve_id": "CVE-2026-79814",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "ClearPass Policy Manager (CPPM)",
      "cwe": null,
      "title": "Local Arbitrary File Write Leading to Local Privilege Escalation in ClearPass Policy Manager OnGuard Agent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79814"
    },
    {
      "rank": 692,
      "cve_id": "CVE-2026-63689",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Container Storage Modules",
      "cwe": "CWE-532",
      "title": "Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63689"
    },
    {
      "rank": 693,
      "cve_id": "CVE-2026-76741",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "AOS-Switch (AOS-S)",
      "cwe": null,
      "title": "Authenticated Buffer Overflow Vulnerabilities lead to Denial-of-Service in AOS-S",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76741"
    },
    {
      "rank": 694,
      "cve_id": "CVE-2026-76749",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "AOS-Switch (AOS-S)",
      "cwe": null,
      "title": "Unauthenticated Sensitive Information Disclosure in AOS-S",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76749"
    },
    {
      "rank": 695,
      "cve_id": "CVE-2026-79815",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "ClearPass Policy Manager (CPPM)",
      "cwe": null,
      "title": "Authenticated Command Injection Vulnerability in the ClearPass Policy Manager OnGuard Agent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79815"
    },
    {
      "rank": 696,
      "cve_id": "CVE-2026-101329",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-284",
      "title": "Langflow OSS is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101329"
    },
    {
      "rank": 697,
      "cve_id": "CVE-2026-102404",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Elasticsearch",
      "cwe": "CWE-400",
      "title": "Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102404"
    },
    {
      "rank": 698,
      "cve_id": "CVE-2026-102409",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Elasticsearch",
      "cwe": "CWE-674",
      "title": "Uncontrolled Recursion in Elasticsearch Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102409"
    },
    {
      "rank": 699,
      "cve_id": "CVE-2026-102411",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Elasticsearch",
      "cwe": "CWE-770",
      "title": "Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102411"
    },
    {
      "rank": 700,
      "cve_id": "CVE-2026-102412",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-863",
      "title": "Incorrect Authorization in Kibana Leading to Sensitive Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102412"
    },
    {
      "rank": 701,
      "cve_id": "CVE-2026-103005",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Elasticsearch",
      "cwe": "CWE-789",
      "title": "Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103005"
    },
    {
      "rank": 702,
      "cve_id": "CVE-2026-103006",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Elasticsearch",
      "cwe": "CWE-674",
      "title": "Uncontrolled Recursion in Elasticsearch Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103006"
    },
    {
      "rank": 703,
      "cve_id": "CVE-2026-103008",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Elasticsearch",
      "cwe": "CWE-674",
      "title": "Uncontrolled Recursion in Elasticsearch Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103008"
    },
    {
      "rank": 704,
      "cve_id": "CVE-2026-105792",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "microsoft",
      "product": "UFO",
      "cwe": "CWE-833",
      "title": "Microsoft UFO: Authenticated task-result request can deadlock UFO server session manager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105792"
    },
    {
      "rank": 705,
      "cve_id": "CVE-2026-106219",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "TeamCity",
      "cwe": "CWE-73",
      "title": "In JetBrains TeamCity before 2026.2.1 missing validation of Git submodule URLs allowed reading local repositories on the server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106219"
    },
    {
      "rank": 706,
      "cve_id": "CVE-2026-106312",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in SignIn in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted Chrome extension. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106312"
    },
    {
      "rank": 707,
      "cve_id": "CVE-2026-106458",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "backstage",
      "product": "backstage",
      "cwe": "CWE-863",
      "title": "Backstage: Inconsistent repository filtering in Bitbucket Server catalog event updates",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106458"
    },
    {
      "rank": 708,
      "cve_id": "CVE-2026-106489",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "backstage",
      "product": "backstage",
      "cwe": "CWE-22",
      "title": "Backstage: Improper authorization enforcement for TechDocs static content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106489"
    },
    {
      "rank": 709,
      "cve_id": "CVE-2026-106490",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "backstage",
      "product": "backstage",
      "cwe": "CWE-22",
      "title": "Backstage: Improper input validation in TechDocs static content requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106490"
    },
    {
      "rank": 710,
      "cve_id": "CVE-2026-106504",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "backstage",
      "product": "backstage",
      "cwe": "CWE-532",
      "title": "Backstage: Sensitive information exposure in scaffolder task logs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106504"
    },
    {
      "rank": 711,
      "cve_id": "CVE-2026-106585",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenBSD",
      "product": "OpenSSH",
      "cwe": "CWE-409",
      "title": "In sshd and ssh in OpenSSH before 10.6, there is no check for whether the maximum packet length is exceeded during decompression of highly compressed data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106585"
    },
    {
      "rank": 712,
      "cve_id": "CVE-2026-105790",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "microsoft",
      "product": "UFO",
      "cwe": "CWE-918",
      "title": "Microsoft UFO: Authenticated Galaxy device registration can bypass WebSocket SSRF IP pinning via redirects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105790"
    },
    {
      "rank": 713,
      "cve_id": "CVE-2026-105848",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "payloadcms",
      "product": "payload",
      "cwe": "CWE-749",
      "title": "Payload: Insufficient Access Control in Stripe REST Proxy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105848"
    },
    {
      "rank": 714,
      "cve_id": "CVE-2026-106462",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "backstage",
      "product": "backstage",
      "cwe": "CWE-441",
      "title": "Backstage: Scaffolder credential handling may allow unintended GitHub authentication fallback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106462"
    },
    {
      "rank": 715,
      "cve_id": "CVE-2026-106491",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "backstage",
      "product": "backstage",
      "cwe": "CWE-20",
      "title": "Backstage: Improper input validation in proxy-backend",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106491"
    },
    {
      "rank": 716,
      "cve_id": "CVE-2026-79816",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "ClearPass Policy Manager (CPPM)",
      "cwe": null,
      "title": "Unauthenticated DOM-Based Cross-Site Scripting (XSS) Vulnerability in the ClearPass Policy Manager Client Interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79816"
    },
    {
      "rank": 717,
      "cve_id": "CVE-2026-106026",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "H. Peter Anvin",
      "product": "tftp-hpa",
      "cwe": "CWE-125",
      "title": "tftp-hpa 5.4 before 6.0 Out-of-Bounds Read via tftpd Remap Jump Rule",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106026"
    },
    {
      "rank": 718,
      "cve_id": "CVE-2026-106063",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-119",
      "title": "Gimp: gimp: heap buffer overflow in dicom export on oversized image dimensions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106063"
    },
    {
      "rank": 719,
      "cve_id": "CVE-2026-101156",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "CloudVision CUE",
      "cwe": "CWE-79",
      "title": "Security Advisory 0192",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101156"
    },
    {
      "rank": 720,
      "cve_id": "CVE-2026-102413",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Elastic Agent and Elastic Defend",
      "cwe": "CWE-248",
      "title": "Uncaught Exception in Elastic Endpoint Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102413"
    },
    {
      "rank": 721,
      "cve_id": "CVE-2026-103778",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Command | Configure (DCC)",
      "cwe": "CWE-321",
      "title": "Dell Command | Configure (DCC), versions prior to 5.2.3.35 contain a Use of Hard-coded Cryptographic Key vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103778"
    },
    {
      "rank": 722,
      "cve_id": "CVE-2026-104046",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-770",
      "title": "Sssd: sssd: denial of service via incomplete identity provider authentication requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104046"
    },
    {
      "rank": 723,
      "cve_id": "CVE-2026-12380",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Akıllı Ticaret Software Technologies Ltd. Co.",
      "product": "E-Commerce Pack",
      "cwe": "CWE-79",
      "title": "Reflected XSS in Akıllı Ticaret's E-Commerce Pack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12380"
    },
    {
      "rank": 724,
      "cve_id": "CVE-2026-63691",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Container Storage Modules",
      "cwe": "CWE-862",
      "title": "Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missing Authorization vulnerability in the Dell CSI Driver for PowerMax - csireverseproxy . An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Unauthorized access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63691"
    },
    {
      "rank": 725,
      "cve_id": "CVE-2026-79812",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "ClearPass Policy Manager (CPPM)",
      "cwe": null,
      "title": "Authenticated Local Denial-of-Service Vulnerability in the OnGuard Agent of ClearPass Policy Manager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79812"
    },
    {
      "rank": 726,
      "cve_id": "CVE-2026-105842",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Uwe Ohse",
      "product": "lrzsz",
      "cwe": "CWE-122",
      "title": "lrzsz before 0.13.0 Heap Buffer Overflow via lrz procheader() Pathname",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105842"
    },
    {
      "rank": 727,
      "cve_id": "CVE-2026-105846",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "payloadcms",
      "product": "payload",
      "cwe": "CWE-601",
      "title": "Payload: Untrusted redirect URL parameter exploit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105846"
    },
    {
      "rank": 728,
      "cve_id": "CVE-2026-102157",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "CloudVision CUE",
      "cwe": "CWE-639",
      "title": "Security Advisory 0190",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102157"
    },
    {
      "rank": 729,
      "cve_id": "CVE-2026-103620",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitHub",
      "product": "Enterprise Server",
      "cwe": "CWE-862",
      "title": "Missing authorization in GitHub Enterprise Server allowed repository writers to replace default branches via GraphQL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103620"
    },
    {
      "rank": 730,
      "cve_id": "CVE-2026-106119",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "langchain-ai",
      "product": "langchainjs",
      "cwe": "CWE-943",
      "title": "LangChain: MongoDBChatMessageHistory query injection can allow cross-session access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106119"
    },
    {
      "rank": 731,
      "cve_id": "CVE-2026-106120",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "harttle",
      "product": "liquidjs",
      "cwe": "CWE-200",
      "title": "LiquidJS: ownPropertyOnly bypass for inherited array indices in first/last/join/reverse/slice/compact, `.first`/`.last`, negative index, and for-loop iteration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106120"
    },
    {
      "rank": 732,
      "cve_id": "CVE-2026-106122",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-java-client",
      "cwe": "CWE-172",
      "title": "RabbitMQ: Malformed UTF-8 in shortstr properties permanently disables RPC consumers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106122"
    },
    {
      "rank": 733,
      "cve_id": "CVE-2026-106111",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SixLabors",
      "product": "ImageSharp",
      "cwe": "CWE-226",
      "title": "ImageSharp: EXR ZIP decoder can expose stale allocator data after a short inflate",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106111"
    },
    {
      "rank": 734,
      "cve_id": "CVE-2026-106183",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in Chromoting in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106183"
    },
    {
      "rank": 735,
      "cve_id": "CVE-2026-106206",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106206"
    },
    {
      "rank": 736,
      "cve_id": "CVE-2026-106222",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in Sync in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106222"
    },
    {
      "rank": 737,
      "cve_id": "CVE-2026-106328",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in PDF in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker leveraging social engineering to obtain sensitive information via a co-installed app. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106328"
    },
    {
      "rank": 738,
      "cve_id": "CVE-2026-105804",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "payloadcms",
      "product": "payload",
      "cwe": "CWE-916",
      "title": "Payload: Password hashes use insufficient PBKDF2 iterations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105804"
    },
    {
      "rank": 739,
      "cve_id": "CVE-2026-106032",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aws",
      "product": "bedrock-agentcore-starter-toolkit",
      "cwe": "CWE-918",
      "title": "Server-side request forgery and local file read via unrestricted external OpenAPI reference resolution in Bedrock AgentCore Starter Toolkit agent import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106032"
    },
    {
      "rank": 740,
      "cve_id": "CVE-2026-106123",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-java-client",
      "cwe": "CWE-509",
      "title": "RabbitMQ Java client: plaintext broker credentials leaked in exception message from ConnectionFactoryConfigurator.load()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106123"
    },
    {
      "rank": 741,
      "cve_id": "CVE-2026-65122",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "TensorRT",
      "cwe": "CWE-125",
      "title": "NVIDIA TensorRT contains a vulnerability where an attacker can cause an out of bounds read. A successful exploit of this vulnerability may lead to denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65122"
    },
    {
      "rank": 742,
      "cve_id": "CVE-2026-70414",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Command | Configure (DCC)",
      "cwe": "CWE-256",
      "title": "Dell Command | Configure (DCC), versions prior to 5.2.3.35, contain a Plaintext Storage of Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70414"
    },
    {
      "rank": 743,
      "cve_id": "CVE-2026-76061",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "cri-o",
      "cwe": "CWE-59",
      "title": "Cri-o: cri-o: bind_mount_prefix intermediate-symlink prefix bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76061"
    },
    {
      "rank": 744,
      "cve_id": "CVE-2026-79817",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "ClearPass Policy Manager (CPPM)",
      "cwe": null,
      "title": "Local Disclosure of Sensitive Information in HPE Networking ClearPass Policy Manager Client Software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79817"
    },
    {
      "rank": 745,
      "cve_id": "CVE-2026-105918",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kusalkasilva",
      "product": "Learning-Management-System",
      "cwe": "CWE-74",
      "title": "Kusalkasilva Learning-Management-System Login Endpoint login.php mysql_error sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105918"
    },
    {
      "rank": 746,
      "cve_id": "CVE-2026-105919",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kusalkasilva",
      "product": "Learning-Management-System",
      "cwe": "CWE-74",
      "title": "Kusalkasilva Learning-Management-System Administrator Login Endpoint login.php mysql_query sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105919"
    },
    {
      "rank": 747,
      "cve_id": "CVE-2026-105920",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kusalkasilva",
      "product": "Learning-Management-System",
      "cwe": "CWE-74",
      "title": "Kusalkasilva Learning-Management-System Student Registration Endpoint student_signup.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105920"
    },
    {
      "rank": 748,
      "cve_id": "CVE-2026-63690",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Container Storage Modules",
      "cwe": "CWE-306",
      "title": "Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missing Authentication for Critical Function vulnerability in the csi-powerflex; csi-powermax; csi-powerstore. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63690"
    },
    {
      "rank": 749,
      "cve_id": "CVE-2026-89182",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea",
      "cwe": "CWE-863",
      "title": "Gitea push-to-create bypass of FORCE_PRIVATE policy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89182"
    },
    {
      "rank": 750,
      "cve_id": "CVE-2026-102407",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Elasticsearch",
      "cwe": "CWE-863",
      "title": "Incorrect Authorization in Elasticsearch Leading to Unauthorized Data Stream Modification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102407"
    },
    {
      "rank": 751,
      "cve_id": "CVE-2026-105789",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "microsoft",
      "product": "UFO",
      "cwe": "CWE-88",
      "title": "Microsoft UFO: Arbitrary file write in the Linux MCP `execute_command` tool",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105789"
    },
    {
      "rank": 752,
      "cve_id": "CVE-2026-106033",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2",
      "cwe": "CWE-79",
      "title": "Ansible: ansible-ui: ansible ui dom xss in /redirect next parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106033"
    },
    {
      "rank": 753,
      "cve_id": "CVE-2026-106179",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "UI misrepresentation in WebAppInstalls in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106179"
    },
    {
      "rank": 754,
      "cve_id": "CVE-2026-106182",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "UI misrepresentation in Paint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106182"
    },
    {
      "rank": 755,
      "cve_id": "CVE-2026-106209",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "UI misrepresentation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106209"
    },
    {
      "rank": 756,
      "cve_id": "CVE-2026-106229",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "UI misrepresentation in FileSystem in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106229"
    },
    {
      "rank": 757,
      "cve_id": "CVE-2026-106232",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "UI misrepresentation in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106232"
    },
    {
      "rank": 758,
      "cve_id": "CVE-2026-106236",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "UI misrepresentation in Chromoting in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via crafted network traffic. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106236"
    },
    {
      "rank": 759,
      "cve_id": "CVE-2026-106246",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106246"
    },
    {
      "rank": 760,
      "cve_id": "CVE-2026-106251",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "UI misrepresentation in Chromoting in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via crafted network traffic. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106251"
    },
    {
      "rank": 761,
      "cve_id": "CVE-2026-106264",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in Web Authentication (Passkeys & Security Keys) in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106264"
    },
    {
      "rank": 762,
      "cve_id": "CVE-2026-106265",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "UI misrepresentation in File in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106265"
    },
    {
      "rank": 763,
      "cve_id": "CVE-2026-106270",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in WebAppInstalls in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106270"
    },
    {
      "rank": 764,
      "cve_id": "CVE-2026-106272",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "UI misrepresentation in Chromoting in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially spoof UI elements via crafted network traffic. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106272"
    },
    {
      "rank": 765,
      "cve_id": "CVE-2026-106276",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "UI misrepresentation in Payments in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106276"
    },
    {
      "rank": 766,
      "cve_id": "CVE-2026-106282",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "UI misrepresentation in WebOTP in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106282"
    },
    {
      "rank": 767,
      "cve_id": "CVE-2026-106285",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "UI misrepresentation in WebAppInstalls in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106285"
    },
    {
      "rank": 768,
      "cve_id": "CVE-2026-106302",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "UI misrepresentation in PermissionElement in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106302"
    },
    {
      "rank": 769,
      "cve_id": "CVE-2026-106305",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "UI misrepresentation in Mobile in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106305"
    },
    {
      "rank": 770,
      "cve_id": "CVE-2026-106311",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-1021",
      "title": "Clickjacking in PermissionElement in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106311"
    },
    {
      "rank": 771,
      "cve_id": "CVE-2026-106316",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "UI misrepresentation in Chromoting in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via crafted network traffic. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106316"
    },
    {
      "rank": 772,
      "cve_id": "CVE-2026-106317",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "UI misrepresentation in FullScreen in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106317"
    },
    {
      "rank": 773,
      "cve_id": "CVE-2026-106333",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in Input in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106333"
    },
    {
      "rank": 774,
      "cve_id": "CVE-2026-106337",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "UI misrepresentation in UI in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106337"
    },
    {
      "rank": 775,
      "cve_id": "CVE-2026-106338",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "UI misrepresentation in PictureInPicture in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106338"
    },
    {
      "rank": 776,
      "cve_id": "CVE-2026-106343",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-754",
      "title": "Improper state validation in Autofill AI in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106343"
    },
    {
      "rank": 777,
      "cve_id": "CVE-2026-106356",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-1021",
      "title": "Clickjacking in EVP in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106356"
    },
    {
      "rank": 778,
      "cve_id": "CVE-2026-106368",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "UI misrepresentation in UI in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106368"
    },
    {
      "rank": 779,
      "cve_id": "CVE-2026-106380",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "UI misrepresentation in UI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106380"
    },
    {
      "rank": 780,
      "cve_id": "CVE-2026-106400",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-1021",
      "title": "Clickjacking in Messages in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106400"
    },
    {
      "rank": 781,
      "cve_id": "CVE-2026-106406",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106406"
    },
    {
      "rank": 782,
      "cve_id": "CVE-2026-106416",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-94",
      "title": "Code injection in Extensions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted Chrome extension. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106416"
    },
    {
      "rank": 783,
      "cve_id": "CVE-2026-106420",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-682",
      "title": "Incorrect calculation in API in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted Chrome extension. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106420"
    },
    {
      "rank": 784,
      "cve_id": "CVE-2026-106463",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "backstage",
      "product": "backstage",
      "cwe": "CWE-863",
      "title": "Backstage: Improper authorization in GitLab organizational user ingestion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106463"
    },
    {
      "rank": 785,
      "cve_id": "CVE-2025-15591",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenText",
      "product": "Content Management",
      "cwe": "CWE-79",
      "title": "Cross-Site Scripting (XSS) vulnerability identified in OpenText™ Content Management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15591"
    },
    {
      "rank": 786,
      "cve_id": "CVE-2026-79818",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "ClearPass Policy Manager (CPPM)",
      "cwe": null,
      "title": "Authentication Bypass in the API Interface Allows Unauthorized Information Disclosure in ClearPass Policy Manager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79818"
    },
    {
      "rank": 787,
      "cve_id": "CVE-2026-82924",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pusula Communication, IT, and Internet Industry and Trade Co. Ltd.",
      "product": "Expert Mail",
      "cwe": "CWE-799",
      "title": "PII Enumeration via Missing Rate Limiting in Pusula Communication's Expert Mail",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82924"
    },
    {
      "rank": 788,
      "cve_id": "CVE-2026-87975",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "djangoproject",
      "product": "Django",
      "cwe": "CWE-639",
      "title": "Privilege abuse in model formsets with editable primary keys",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87975"
    },
    {
      "rank": 789,
      "cve_id": "CVE-2026-101151",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "CloudVision Portal",
      "cwe": "CWE-601",
      "title": "Security Advisory 0187",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101151"
    },
    {
      "rank": 790,
      "cve_id": "CVE-2026-104047",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-140",
      "title": "Sssd: sssd: information disclosure via query injection in entra id lookups",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104047"
    },
    {
      "rank": 791,
      "cve_id": "CVE-2026-105239",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache log4net",
      "cwe": "CWE-158",
      "title": "Apache log4net: NUL character truncates EventLogAppender records",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105239"
    },
    {
      "rank": 792,
      "cve_id": "CVE-2026-105240",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache log4net",
      "cwe": "CWE-158",
      "title": "Apache log4net: NUL character truncates OutputDebugStringAppender records",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105240"
    },
    {
      "rank": 793,
      "cve_id": "CVE-2026-105241",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache log4net",
      "cwe": "CWE-176",
      "title": "Apache log4net: Unencodable content discards a whole SmtpPickupDirAppender batch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105241"
    },
    {
      "rank": 794,
      "cve_id": "CVE-2026-105242",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache log4net",
      "cwe": "CWE-755",
      "title": "Apache log4net: Request validation failure drops the event in the aspnet-request converter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105242"
    },
    {
      "rank": 795,
      "cve_id": "CVE-2026-105243",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache log4net",
      "cwe": "CWE-778",
      "title": "Apache log4net: Oversize EventLogAppender record silently discarded",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105243"
    },
    {
      "rank": 796,
      "cve_id": "CVE-2026-105244",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache log4net",
      "cwe": "CWE-116",
      "title": "Apache log4net: RemoteSyslogAppender silently deletes non-ASCII content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105244"
    },
    {
      "rank": 797,
      "cve_id": "CVE-2026-105836",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webkul",
      "product": "QloApps",
      "cwe": "CWE-639",
      "title": "QloApps through 1.7.0 Authorization Bypass via ajaxProcessBulkUpdateRooms",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105836"
    },
    {
      "rank": 798,
      "cve_id": "CVE-2026-105864",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "payloadcms",
      "product": "payload",
      "cwe": "CWE-863",
      "title": "Payload: Cross-tenant create in @payloadcms/plugin-multi-tenant",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105864"
    },
    {
      "rank": 799,
      "cve_id": "CVE-2026-106114",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SixLabors",
      "product": "ImageSharp",
      "cwe": "CWE-789",
      "title": "ImageSharp: ICC CLUT parsing allocates from unvalidated channel and grid dimensions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106114"
    },
    {
      "rank": 800,
      "cve_id": "CVE-2026-106116",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SixLabors",
      "product": "ImageSharp",
      "cwe": "CWE-835",
      "title": "ImageSharp: BigTIFF IFD count can keep a decoder thread in a non-progressing loop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106116"
    },
    {
      "rank": 801,
      "cve_id": "CVE-2026-106181",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-706",
      "title": "Incorrect reference resolution in DevTools in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106181"
    },
    {
      "rank": 802,
      "cve_id": "CVE-2026-106214",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Information leak in Proxy in Google Chrome on on Windows prior to 155.0.8059.39 allowed an adjacent attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106214"
    },
    {
      "rank": 803,
      "cve_id": "CVE-2026-106230",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-706",
      "title": "Incorrect reference resolution in Offline in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106230"
    },
    {
      "rank": 804,
      "cve_id": "CVE-2026-106243",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-459",
      "title": "Incomplete cleanup in Proxy Auth in Google Chrome prior to 155.0.8059.39 allowed an adjacent attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106243"
    },
    {
      "rank": 805,
      "cve_id": "CVE-2026-106303",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-203",
      "title": "Observable discrepancy in Autofill AI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106303"
    },
    {
      "rank": 806,
      "cve_id": "CVE-2026-106351",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-203",
      "title": "Observable discrepancy in Safebrowsing in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106351"
    },
    {
      "rank": 807,
      "cve_id": "CVE-2026-106355",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in Media in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106355"
    },
    {
      "rank": 808,
      "cve_id": "CVE-2026-106364",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in Omnibox in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106364"
    },
    {
      "rank": 809,
      "cve_id": "CVE-2026-106388",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in DataTransfer in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106388"
    },
    {
      "rank": 810,
      "cve_id": "CVE-2026-106450",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yawkat",
      "product": "lz4-java",
      "cwe": "CWE-770",
      "title": "yawkat LZ4 Java: LZ4FrameInputStream reallocates block buffers for every frame, allowing CPU and GC amplification from small inputs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106450"
    },
    {
      "rank": 811,
      "cve_id": "CVE-2026-106452",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yawkat",
      "product": "lz4-java",
      "cwe": "CWE-789",
      "title": "yawkat LZ4 Java: LZ4BlockInputStream allocates an unvalidated compressed length from the stream header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106452"
    },
    {
      "rank": 812,
      "cve_id": "CVE-2026-106453",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yawkat",
      "product": "lz4-java",
      "cwe": "CWE-789",
      "title": "yawkat LZ4 Java: LZ4DecompressorWithLength allocates the unvalidated size from the 4-byte length header, so a 5-byte input triggers a 1 GiB allocation and OutOfMemoryError",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106453"
    },
    {
      "rank": 813,
      "cve_id": "CVE-2026-106502",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "backstage",
      "product": "backstage",
      "cwe": "CWE-532",
      "title": "Backstage: Sensitive information may be exposed in Scaffolder task failure events",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106502"
    },
    {
      "rank": 814,
      "cve_id": "CVE-2026-106506",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "backstage",
      "product": "backstage",
      "cwe": "CWE-202",
      "title": "Backstage: Improper input validation in scaffolder task list ordering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106506"
    },
    {
      "rank": 815,
      "cve_id": "CVE-2026-106507",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "backstage",
      "product": "backstage",
      "cwe": "CWE-59",
      "title": "Backstage: TechDocs arbitrary file read via mkdocs snippets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106507"
    },
    {
      "rank": 816,
      "cve_id": "CVE-2026-106508",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "backstage",
      "product": "backstage",
      "cwe": "CWE-22",
      "title": "Backstage: Potential file exposure through local TechDocs publisher",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106508"
    },
    {
      "rank": 817,
      "cve_id": "CVE-2026-34498",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Johnson Controls",
      "product": "Illustra Standard - L4L China",
      "cwe": "CWE-20",
      "title": "L4L",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34498"
    },
    {
      "rank": 818,
      "cve_id": "CVE-2026-101149",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "CloudVision Portal",
      "cwe": "CWE-918",
      "title": "Security Advisory 0186",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101149"
    },
    {
      "rank": 819,
      "cve_id": "CVE-2026-101150",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "CloudVision Portal",
      "cwe": "CWE-918",
      "title": "Security Advisory 0186",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101150"
    },
    {
      "rank": 820,
      "cve_id": "CVE-2026-105950",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getformwork",
      "product": "formwork",
      "cwe": "CWE-79",
      "title": "getformwork URI Sanitizer DomSanitizer.php sanitizeNodeAttribute cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105950"
    },
    {
      "rank": 821,
      "cve_id": "CVE-2026-106254",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Information leak in Mobile in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker to obtain sensitive information via a co-installed app. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106254"
    },
    {
      "rank": 822,
      "cve_id": "CVE-2026-106313",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in Browser in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker leveraging social engineering to obtain sensitive information via a co-installed app. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106313"
    },
    {
      "rank": 823,
      "cve_id": "CVE-2026-95153",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-200",
      "title": "An issue in Bludit CMS 3.22.0 allows a remote attacker to obtain sensitive information via the /admin/ajax/clippy and /admin/ajax/save-as-draft endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95153"
    },
    {
      "rank": 824,
      "cve_id": "CVE-2026-106121",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-java-client",
      "cwe": "CWE-835",
      "title": "RabbitMQ: JSONReader in the default JSON-RPC mapper never terminates on truncated input, causing DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106121"
    },
    {
      "rank": 825,
      "cve_id": "CVE-2026-106499",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "backstage",
      "product": "backstage",
      "cwe": "CWE-532",
      "title": "Backstage: Secret-derived values may be exposed in scaffolder task logs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106499"
    },
    {
      "rank": 826,
      "cve_id": "CVE-2026-106402",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in Extensions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted Chrome extension. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106402"
    },
    {
      "rank": 827,
      "cve_id": "CVE-2026-106456",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "backstage",
      "product": "backstage",
      "cwe": "CWE-863",
      "title": "Backstage: Inconsistent credential enforcement for overlapping proxy routes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106456"
    },
    {
      "rank": 828,
      "cve_id": "CVE-2026-88252",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-835",
      "title": "Sssd: sssd: denial of service via responder connection retry loop during file descriptor exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88252"
    },
    {
      "rank": 829,
      "cve_id": "CVE-2026-104045",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-772",
      "title": "Sssd: sssd: denial of service via race condition in autofs responder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104045"
    },
    {
      "rank": 830,
      "cve_id": "CVE-2026-106444",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "handlebars-lang",
      "product": "handlebars.js",
      "cwe": "CWE-116",
      "title": "Handlebars: JavaScript Injection via Unsafe Inline Embedding of Precompiled Templates",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106444"
    },
    {
      "rank": 831,
      "cve_id": "CVE-2026-106192",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Information leak in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a local attacker to obtain sensitive information via physical access. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106192"
    },
    {
      "rank": 832,
      "cve_id": "CVE-2026-106340",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in CredentialProvider in Google Chrome on on Windows prior to 155.0.8059.39 allowed a local attacker to obtain sensitive information via physical access. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106340"
    },
    {
      "rank": 833,
      "cve_id": "CVE-2026-0198",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-862",
      "title": "In is_pd_allowed of gem_msg.c, there is a possible permission bypass due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0198"
    },
    {
      "rank": 834,
      "cve_id": "CVE-2026-55307",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-269",
      "title": "In kdn_set_sysregs_prot of hwcrypto-kdn.c, there is a possible information disclosure due to a logic error in the code. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55307"
    },
    {
      "rank": 835,
      "cve_id": "CVE-2026-106494",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "backstage",
      "product": "backstage",
      "cwe": "CWE-22",
      "title": "Backstage: Improper input validation in cloud storage URL readers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106494"
    },
    {
      "rank": 836,
      "cve_id": "CVE-2026-96400",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea",
      "cwe": "CWE-918",
      "title": "Gitea migration SSRF to reserved addresses through ALLOWED_DOMAINS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96400"
    },
    {
      "rank": 837,
      "cve_id": "CVE-2026-102408",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Elasticsearch",
      "cwe": "CWE-1333",
      "title": "Inefficient Regular Expression Complexity in Elasticsearch Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102408"
    },
    {
      "rank": 838,
      "cve_id": "CVE-2026-102410",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-862",
      "title": "Missing Authorization in Kibana Leading to Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102410"
    },
    {
      "rank": 839,
      "cve_id": "CVE-2026-106184",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-908",
      "title": "Uninitialized resource in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106184"
    },
    {
      "rank": 840,
      "cve_id": "CVE-2026-106213",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-362",
      "title": "Race condition in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106213"
    },
    {
      "rank": 841,
      "cve_id": "CVE-2026-106217",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in Google Lens in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106217"
    },
    {
      "rank": 842,
      "cve_id": "CVE-2026-106245",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-908",
      "title": "Uninitialized resource in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106245"
    },
    {
      "rank": 843,
      "cve_id": "CVE-2026-106253",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in Extensions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted Chrome extension. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106253"
    },
    {
      "rank": 844,
      "cve_id": "CVE-2026-106260",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in DevTools in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106260"
    },
    {
      "rank": 845,
      "cve_id": "CVE-2026-106277",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Information leak in Animation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106277"
    },
    {
      "rank": 846,
      "cve_id": "CVE-2026-106321",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Information leak in Editing in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106321"
    },
    {
      "rank": 847,
      "cve_id": "CVE-2026-106325",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-706",
      "title": "Incorrect reference resolution in Core in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106325"
    },
    {
      "rank": 848,
      "cve_id": "CVE-2026-106330",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Information leak in Paint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106330"
    },
    {
      "rank": 849,
      "cve_id": "CVE-2026-106332",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-190",
      "title": "Integer overflow in Compositing in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106332"
    },
    {
      "rank": 850,
      "cve_id": "CVE-2026-106336",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-203",
      "title": "Observable discrepancy in Paint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106336"
    },
    {
      "rank": 851,
      "cve_id": "CVE-2026-106354",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-668",
      "title": "Improper resource exposure in Extensions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106354"
    },
    {
      "rank": 852,
      "cve_id": "CVE-2026-106360",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Information leak in Payments in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106360"
    },
    {
      "rank": 853,
      "cve_id": "CVE-2026-106379",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-908",
      "title": "Uninitialized resource in Skia in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106379"
    },
    {
      "rank": 854,
      "cve_id": "CVE-2026-106390",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-684",
      "title": "Incorrect provision of specified functionality in SanitizerAPI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106390"
    },
    {
      "rank": 855,
      "cve_id": "CVE-2026-106392",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Information leak in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106392"
    },
    {
      "rank": 856,
      "cve_id": "CVE-2026-106394",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-459",
      "title": "Incomplete cleanup in Glic in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106394"
    },
    {
      "rank": 857,
      "cve_id": "CVE-2026-106398",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106398"
    },
    {
      "rank": 858,
      "cve_id": "CVE-2026-106415",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Information leak in Enterprise in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106415"
    },
    {
      "rank": 859,
      "cve_id": "CVE-2026-106454",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "twisted",
      "product": "twisted",
      "cwe": "CWE-1333",
      "title": "Twisted: IMAP wildcardToRegexp() ReDoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106454"
    },
    {
      "rank": 860,
      "cve_id": "CVE-2026-106461",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "backstage",
      "product": "backstage",
      "cwe": "CWE-863",
      "title": "Backstage: Incorrect authorization in scaffolder task listing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106461"
    },
    {
      "rank": 861,
      "cve_id": "CVE-2026-106497",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "backstage",
      "product": "backstage",
      "cwe": "CWE-178",
      "title": "Backstage: Inconsistent catalog property permission evaluation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106497"
    },
    {
      "rank": 862,
      "cve_id": "CVE-2026-106187",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106187"
    },
    {
      "rank": 863,
      "cve_id": "CVE-2026-106226",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Improper input validation in Compositing in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106226"
    },
    {
      "rank": 864,
      "cve_id": "CVE-2026-106262",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-459",
      "title": "Incomplete cleanup in GetUserMedia in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106262"
    },
    {
      "rank": 865,
      "cve_id": "CVE-2026-106295",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in Unbounded Element in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106295"
    },
    {
      "rank": 866,
      "cve_id": "CVE-2026-106320",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-672",
      "title": "Use of released resource in UI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106320"
    },
    {
      "rank": 867,
      "cve_id": "CVE-2026-106345",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-672",
      "title": "Use of released resource in Session in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106345"
    },
    {
      "rank": 868,
      "cve_id": "CVE-2026-106391",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in WebShare in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106391"
    },
    {
      "rank": 869,
      "cve_id": "CVE-2026-106410",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106410"
    },
    {
      "rank": 870,
      "cve_id": "CVE-2026-106413",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-367",
      "title": "Race condition in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106413"
    },
    {
      "rank": 871,
      "cve_id": "CVE-2026-106552",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenBSD",
      "product": "OpenSSH",
      "cwe": "CWE-23",
      "title": "In sftp in OpenSSH before 10.6, a server can trigger directory traversal (causing files to be written to unintended locations) during a recursive copy operation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106552"
    },
    {
      "rank": 872,
      "cve_id": "CVE-2026-106109",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "quasarframework",
      "product": "quasar",
      "cwe": "CWE-22",
      "title": "Quasar Framework: App Vite build cleanup can recursively remove unsafe configured output directories",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106109"
    },
    {
      "rank": 873,
      "cve_id": "CVE-2026-105800",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "i18next",
      "product": "i18next-http-backend",
      "cwe": "CWE-74",
      "title": "i18next-http-backend incomplete URL validation permits SSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105800"
    },
    {
      "rank": 874,
      "cve_id": "CVE-2026-106449",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yawkat",
      "product": "lz4-java",
      "cwe": "CWE-674",
      "title": "yawkat LZ4 Java: LZ4BlockInputStream with stopOnEmptyBlock=false recurses once per empty block, causing StackOverflowError",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106449"
    },
    {
      "rank": 875,
      "cve_id": "CVE-2026-106582",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenBSD",
      "product": "OpenSSH",
      "cwe": "CWE-514",
      "title": "In sshd and ssh in OpenSSH before 10.6, an LZ77 dictionary coder can be used even though this is contraindicated by the arXiv 2609.07709 \"Crossing the Streams\" findings.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106582"
    },
    {
      "rank": 876,
      "cve_id": "CVE-2026-106587",
      "cvss_base": 3.6,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenBSD",
      "product": "OpenSSH",
      "cwe": "CWE-843",
      "title": "In sshd in OpenSSH before 10.6, the value \"none\" for a configuration option is sometimes interpreted as a filename but was intended to mean that a feature is disabled.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106587"
    },
    {
      "rank": 877,
      "cve_id": "CVE-2026-56596",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "HCL BigFix Service Management",
      "cwe": "CWE-20",
      "title": "HCL BigFix Service Management is affected by multiple security vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56596"
    },
    {
      "rank": 878,
      "cve_id": "CVE-2026-106487",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "backstage",
      "product": "backstage",
      "cwe": "CWE-441",
      "title": "Backstage: Unsupported catalog cluster authentication mode in kubernetes backend",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106487"
    },
    {
      "rank": 879,
      "cve_id": "CVE-2026-105795",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "microsoft",
      "product": "kiota",
      "cwe": "CWE-22",
      "title": "Kiota: Unsafe oauth_card_path references in Kiota-generated API plugin manifests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105795"
    },
    {
      "rank": 880,
      "cve_id": "CVE-2026-106101",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "quasarframework",
      "product": "quasar",
      "cwe": "CWE-843",
      "title": "Quasar Framework: DOM Clobbering in Quasar openURL() SafariViewController Integration Causes Client-Side Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106101"
    },
    {
      "rank": 881,
      "cve_id": "CVE-2026-106180",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-203",
      "title": "Observable discrepancy in Animation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106180"
    },
    {
      "rank": 882,
      "cve_id": "CVE-2026-106210",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-203",
      "title": "Observable discrepancy in Scroll in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted Chrome extension. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106210"
    },
    {
      "rank": 883,
      "cve_id": "CVE-2026-106224",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in Google Lens in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106224"
    },
    {
      "rank": 884,
      "cve_id": "CVE-2026-106339",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-672",
      "title": "Use of released resource in Core in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106339"
    },
    {
      "rank": 885,
      "cve_id": "CVE-2026-106496",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "backstage",
      "product": "backstage",
      "cwe": "CWE-22",
      "title": "Backstage: Inconsistent enforcement of allowed location types during catalog processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106496"
    },
    {
      "rank": 886,
      "cve_id": "CVE-2026-106588",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenBSD",
      "product": "OpenSSH",
      "cwe": "CWE-653",
      "title": "In sshd in OpenSSH through 10.6, use of the macOS 27 (or later) SDK has the side effect of loss of sandboxing, which is potentially unexpected.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106588"
    },
    {
      "rank": 887,
      "cve_id": "CVE-2026-106493",
      "cvss_base": 3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "backstage",
      "product": "backstage",
      "cwe": "CWE-22",
      "title": "Backstage: Cloud storage catalog locations may cross configured storage boundaries",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106493"
    },
    {
      "rank": 888,
      "cve_id": "CVE-2026-106589",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenBSD",
      "product": "OpenSSH",
      "cwe": "CWE-272",
      "title": "In sshd in OpenSSH through 10.6, in certain environments such as QNX 6 and SCO OpenServer 5, sshd-session can unexpectedly have root privileges. This is related to the GatewayPorts and StreamLocalForwarding configuration options, and lack of support for file-descriptor passing and unprivileged allocation of PTY devices.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106589"
    },
    {
      "rank": 889,
      "cve_id": "CVE-2026-106583",
      "cvss_base": 2.5,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenBSD",
      "product": "OpenSSH",
      "cwe": "CWE-99",
      "title": "In ssh in OpenSSH before 10.6, a $ or \\ character can occur in a command-line username, leading to injection.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106583"
    },
    {
      "rank": 890,
      "cve_id": "CVE-2026-106584",
      "cvss_base": 2.5,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenBSD",
      "product": "OpenSSH",
      "cwe": "CWE-193",
      "title": "In ssh-keygen in OpenSSH before 10.6, certificates could have incorrect expiration times because of Daylight Saving mishandling. There can be a slightly more severe effect on users in certain Antarctic locations.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106584"
    },
    {
      "rank": 891,
      "cve_id": "CVE-2026-106586",
      "cvss_base": 2.5,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenBSD",
      "product": "OpenSSH",
      "cwe": "CWE-670",
      "title": "In sshd in OpenSSH before 10.6, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not, a different vulnerability than CVE-2026-73283.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106586"
    },
    {
      "rank": 892,
      "cve_id": "CVE-2026-102164",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "Wi-Fi Access Points",
      "cwe": "CWE-125",
      "title": "Security Advisory 0196",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102164"
    },
    {
      "rank": 893,
      "cve_id": "CVE-2026-105111",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Commons BCEL",
      "cwe": "CWE-79",
      "title": "Apache Commons BCEL: Class2HTML emits unescaped class strings, enabling stored XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105111"
    },
    {
      "rank": 894,
      "cve_id": "CVE-2026-105799",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "langchain-ai",
      "product": "langchainjs",
      "cwe": "CWE-943",
      "title": "LangChain: RediSearch Filter Injection via Unescaped Tag/Text Values",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105799"
    },
    {
      "rank": 895,
      "cve_id": "CVE-2026-106553",
      "cvss_base": 2.2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenBSD",
      "product": "OpenSSH",
      "cwe": "CWE-669",
      "title": "In sshd in OpenSSH before 10.6, credentials can incorrectly persist after failure of a GSSAPIAuthentication authentication attempt.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106553"
    },
    {
      "rank": 896,
      "cve_id": "CVE-2026-106555",
      "cvss_base": 2.2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenBSD",
      "product": "OpenSSH",
      "cwe": "CWE-669",
      "title": "In sshd in OpenSSH before 10.6, GSSAPIAuthentication authentication state can incorrectly be persisted across authentication attempts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106555"
    },
    {
      "rank": 897,
      "cve_id": "CVE-2026-105921",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kusalkasilva",
      "product": "Learning-Management-System",
      "cwe": "CWE-74",
      "title": "Kusalkasilva Learning-Management-System search_class.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105921"
    },
    {
      "rank": 898,
      "cve_id": "CVE-2026-105922",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vLLM",
      "cwe": "CWE-404",
      "title": "vllm-project vLLM Penalty utils.py get_token_bin_counts_and_mask denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105922"
    },
    {
      "rank": 899,
      "cve_id": "CVE-2026-105957",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Performance Indicator System",
      "cwe": "CWE-74",
      "title": "SourceCodester Performance Indicator System view_product.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105957"
    },
    {
      "rank": 900,
      "cve_id": "CVE-2026-75818",
      "cvss_base": 1.8,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU",
      "product": "Aspell",
      "cwe": "CWE-122",
      "title": "Heap Buffer Overflow in GNU Aspell's prezip utility",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75818"
    },
    {
      "rank": 901,
      "cve_id": "CVE-2026-75819",
      "cvss_base": 1.8,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU",
      "product": "Aspell",
      "cwe": "CWE-125",
      "title": "Out-of-bounds Read in GNU Aspell",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75819"
    },
    {
      "rank": 902,
      "cve_id": "CVE-2026-75820",
      "cvss_base": 1.8,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU",
      "product": "Aspell",
      "cwe": "CWE-190",
      "title": "Integer Truncation Leading to Heap Corruption in GNU Aspell",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75820"
    },
    {
      "rank": 903,
      "cve_id": "CVE-2025-45871",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "LogicalDOC Enterprise up to and for 9.1.1 is vulnerable to blind SQL injection in the WorkflowsDataServlet component, allowing authenticated user to manipulate SQL queries via crafted workflow template name.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-45871"
    },
    {
      "rank": 904,
      "cve_id": "CVE-2025-71383",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Dbit WIFI4 N300 1.0.0 devices allow the management interface to be crashed via a request (from the local Wi-Fi network) that lacks a /api/login username or password field. This occurs because of an error in a JSON parser.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71383"
    },
    {
      "rank": 905,
      "cve_id": "CVE-2025-71384",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Dbit WIFI4 N300 1.0.0 devices allows administrators (from the local Wi-Fi network) to execute OS commands by leveraging a stack-based buffer overflow via the /api/addStaticDHCP comment field,",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71384"
    },
    {
      "rank": 906,
      "cve_id": "CVE-2026-9226",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Devolutions",
      "product": "Server",
      "cwe": "CWE-294",
      "title": "Authentication bypass in the Azure AD external login flow in Devolutions Server 2026.3.7.0 and earlier allows a remote attacker to take over a user's account via replay of a captured login-session token exposed in a redirect URL.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9226"
    },
    {
      "rank": 907,
      "cve_id": "CVE-2026-70357",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea",
      "cwe": "CWE-918",
      "title": "Gitea repository migration SSRF through DNS rebinding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70357"
    },
    {
      "rank": 908,
      "cve_id": "CVE-2026-73278",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea",
      "cwe": "CWE-287",
      "title": "Gitea WebAuthn bypass during OAuth and OIDC sign-in",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73278"
    },
    {
      "rank": 909,
      "cve_id": "CVE-2026-79960",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea",
      "cwe": "CWE-863",
      "title": "Gitea deploy key pushes acting as the repository owner",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79960"
    },
    {
      "rank": 910,
      "cve_id": "CVE-2026-80048",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-770",
      "title": "Sssd: sssd-kcm: local denial of service via excessive memory preallocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80048"
    },
    {
      "rank": 911,
      "cve_id": "CVE-2026-86684",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea",
      "cwe": "CWE-863",
      "title": "Gitea push mirror local path check uses the repository owner",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86684"
    },
    {
      "rank": 912,
      "cve_id": "CVE-2026-89430",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea",
      "cwe": "CWE-367",
      "title": "Gitea push mirror SSRF and forced writes to internal Git hosts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89430"
    },
    {
      "rank": 913,
      "cve_id": "CVE-2026-94205",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea",
      "cwe": "CWE-441",
      "title": "Gitea fork workflow approval bypass through maintainer-triggered events",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94205"
    },
    {
      "rank": 914,
      "cve_id": "CVE-2026-95106",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea",
      "cwe": null,
      "title": "Gitea review and execution mismatch through duplicate tree entries",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95106"
    },
    {
      "rank": 915,
      "cve_id": "CVE-2026-95112",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea",
      "cwe": null,
      "title": "Gitea issue reference parsing CPU exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95112"
    },
    {
      "rank": 916,
      "cve_id": "CVE-2026-96399",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea",
      "cwe": "CWE-125",
      "title": "Gitea denial of service through external issue tracker patterns",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96399"
    },
    {
      "rank": 917,
      "cve_id": "CVE-2026-96404",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea",
      "cwe": null,
      "title": "Gitea installer authentication bypass for existing accounts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96404"
    },
    {
      "rank": 918,
      "cve_id": "CVE-2026-96580",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea",
      "cwe": "CWE-400",
      "title": "Gitea Actions memory exhaustion through large static matrices",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96580"
    },
    {
      "rank": 919,
      "cve_id": "CVE-2026-96589",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea",
      "cwe": "CWE-672",
      "title": "Gitea private repository access retained after rejected transfer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96589"
    },
    {
      "rank": 920,
      "cve_id": "CVE-2026-96594",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea",
      "cwe": "CWE-79",
      "title": "Gitea repository media API stored XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96594"
    },
    {
      "rank": 921,
      "cve_id": "CVE-2026-97208",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea",
      "cwe": "CWE-863",
      "title": "Gitea push mirror API bypass of DISABLE_NEW_PUSH policy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97208"
    },
    {
      "rank": 922,
      "cve_id": "CVE-2026-97626",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea",
      "cwe": "CWE-200",
      "title": "Gitea profile feed disclosure bypassing user visibility",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97626"
    },
    {
      "rank": 923,
      "cve_id": "CVE-2026-101023",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea",
      "cwe": null,
      "title": "Gitea OAuth2 refresh token grant accepts access tokens",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101023"
    },
    {
      "rank": 924,
      "cve_id": "CVE-2026-101029",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea",
      "cwe": "CWE-209",
      "title": "Gitea migration and pull mirror SSRF through multi-answer DNS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101029"
    },
    {
      "rank": 925,
      "cve_id": "CVE-2026-103059",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea",
      "cwe": null,
      "title": "Gitea built-in SSH server authentication bypass through key case folding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103059"
    },
    {
      "rank": 926,
      "cve_id": "CVE-2026-103504",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea",
      "cwe": "CWE-272",
      "title": "Gitea API team demotion not applied to unit permissions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103504"
    },
    {
      "rank": 927,
      "cve_id": "CVE-2026-103667",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea",
      "cwe": "CWE-79",
      "title": "Gitea container registry stored XSS through blob media type",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103667"
    },
    {
      "rank": 928,
      "cve_id": "CVE-2026-103670",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea",
      "cwe": null,
      "title": "Gitea trusted workflow cancellation by unapproved fork runs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103670"
    },
    {
      "rank": 929,
      "cve_id": "CVE-2026-104626",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea",
      "cwe": "CWE-841",
      "title": "Gitea fork workflow job revival through later approval",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104626"
    },
    {
      "rank": 930,
      "cve_id": "CVE-2026-104632",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea",
      "cwe": null,
      "title": "Gitea fork workflow approval bypass through cancel and rerun",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104632"
    },
    {
      "rank": 931,
      "cve_id": "CVE-2026-104633",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea",
      "cwe": "CWE-400",
      "title": "Gitea migration memory exhaustion from zero page size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104633"
    },
    {
      "rank": 932,
      "cve_id": "CVE-2026-104636",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea",
      "cwe": "CWE-918",
      "title": "Gitea SSRF through Git HTTP redirects in mirrors and fetches",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104636"
    },
    {
      "rank": 933,
      "cve_id": "CVE-2026-105267",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea",
      "cwe": "CWE-732",
      "title": "Gitea tag delete route deletes releases without release permission",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105267"
    },
    {
      "rank": 934,
      "cve_id": "CVE-2026-105268",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea",
      "cwe": "CWE-639",
      "title": "Gitea issue attachment API allows changing comment attachments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105268"
    },
    {
      "rank": 935,
      "cve_id": "CVE-2026-105488",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Devolutions",
      "product": "Server",
      "cwe": "CWE-862",
      "title": "Missing authorization in the global vault in Devolutions Server 2026.3.7.0 and earlier allows an authenticated user with only the global vault view permission to modify and delete global contact and folder entries.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105488"
    },
    {
      "rank": 936,
      "cve_id": "CVE-2026-106016",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Mitigation bypass in the File Handling component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106016"
    },
    {
      "rank": 937,
      "cve_id": "CVE-2026-106185",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Improper input validation in Viz in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106185"
    },
    {
      "rank": 938,
      "cve_id": "CVE-2026-106188",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-441",
      "title": "Confused deputy in SignIn in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106188"
    },
    {
      "rank": 939,
      "cve_id": "CVE-2026-106189",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-94",
      "title": "Code injection in ReaderMode in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106189"
    },
    {
      "rank": 940,
      "cve_id": "CVE-2026-106195",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in Chromoting in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106195"
    },
    {
      "rank": 941,
      "cve_id": "CVE-2026-106196",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in Navigation in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106196"
    },
    {
      "rank": 942,
      "cve_id": "CVE-2026-106198",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in FileSystem in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106198"
    },
    {
      "rank": 943,
      "cve_id": "CVE-2026-106199",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in Actor in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially bypass site isolation via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106199"
    },
    {
      "rank": 944,
      "cve_id": "CVE-2026-106202",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-908",
      "title": "Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106202"
    },
    {
      "rank": 945,
      "cve_id": "CVE-2026-106205",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in Passwords in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106205"
    },
    {
      "rank": 946,
      "cve_id": "CVE-2026-106208",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in API in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted Chrome extension. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106208"
    },
    {
      "rank": 947,
      "cve_id": "CVE-2026-106215",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-908",
      "title": "Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106215"
    },
    {
      "rank": 948,
      "cve_id": "CVE-2026-106216",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-352",
      "title": "Cross-site request forgery in ReadingList in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106216"
    },
    {
      "rank": 949,
      "cve_id": "CVE-2026-106221",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-441",
      "title": "Confused deputy in WebAPKs in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106221"
    },
    {
      "rank": 950,
      "cve_id": "CVE-2026-106223",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-908",
      "title": "Uninitialized resource in GPU in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106223"
    },
    {
      "rank": 951,
      "cve_id": "CVE-2026-106231",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-908",
      "title": "Uninitialized resource in Dawn in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106231"
    },
    {
      "rank": 952,
      "cve_id": "CVE-2026-106237",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Information leak in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106237"
    },
    {
      "rank": 953,
      "cve_id": "CVE-2026-106242",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Information leak in Omnibox in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to leak sensitive information via crafted network traffic. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106242"
    },
    {
      "rank": 954,
      "cve_id": "CVE-2026-106244",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106244"
    },
    {
      "rank": 955,
      "cve_id": "CVE-2026-106250",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in Actor in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106250"
    },
    {
      "rank": 956,
      "cve_id": "CVE-2026-106258",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-908",
      "title": "Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106258"
    },
    {
      "rank": 957,
      "cve_id": "CVE-2026-106259",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in PermissionElement in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106259"
    },
    {
      "rank": 958,
      "cve_id": "CVE-2026-106261",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-908",
      "title": "Uninitialized resource in Video in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106261"
    },
    {
      "rank": 959,
      "cve_id": "CVE-2026-106263",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Improper input validation in SignIn in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106263"
    },
    {
      "rank": 960,
      "cve_id": "CVE-2026-106266",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-441",
      "title": "Confused deputy in Contextual Tasks in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106266"
    },
    {
      "rank": 961,
      "cve_id": "CVE-2026-106267",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in Network in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106267"
    },
    {
      "rank": 962,
      "cve_id": "CVE-2026-106271",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in Workers in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted PDF file. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106271"
    },
    {
      "rank": 963,
      "cve_id": "CVE-2026-106273",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-908",
      "title": "Uninitialized resource in Video in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106273"
    },
    {
      "rank": 964,
      "cve_id": "CVE-2026-106275",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-908",
      "title": "Uninitialized resource in GPU in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106275"
    },
    {
      "rank": 965,
      "cve_id": "CVE-2026-106280",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in PermissionElement in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106280"
    },
    {
      "rank": 966,
      "cve_id": "CVE-2026-106284",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in Printing in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106284"
    },
    {
      "rank": 967,
      "cve_id": "CVE-2026-106286",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-441",
      "title": "Confused deputy in Omnibox in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy via crafted network traffic. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106286"
    },
    {
      "rank": 968,
      "cve_id": "CVE-2026-106287",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-221",
      "title": "Information loss in CORS in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy via crafted network traffic. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106287"
    },
    {
      "rank": 969,
      "cve_id": "CVE-2026-106288",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106288"
    },
    {
      "rank": 970,
      "cve_id": "CVE-2026-106289",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in FedCM in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106289"
    },
    {
      "rank": 971,
      "cve_id": "CVE-2026-106290",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-908",
      "title": "Uninitialized resource in GPU in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106290"
    },
    {
      "rank": 972,
      "cve_id": "CVE-2026-106294",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-459",
      "title": "Incomplete cleanup in Chromoting in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106294"
    },
    {
      "rank": 973,
      "cve_id": "CVE-2026-106296",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-269",
      "title": "Improper privilege management in UI in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106296"
    },
    {
      "rank": 974,
      "cve_id": "CVE-2026-106297",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in Scheduling in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106297"
    },
    {
      "rank": 975,
      "cve_id": "CVE-2026-106299",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Improper input validation in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106299"
    },
    {
      "rank": 976,
      "cve_id": "CVE-2026-106300",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-367",
      "title": "Race condition in CacheStorage in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106300"
    },
    {
      "rank": 977,
      "cve_id": "CVE-2026-106301",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-441",
      "title": "Confused deputy in Contextual Tasks in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106301"
    },
    {
      "rank": 978,
      "cve_id": "CVE-2026-106304",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106304"
    },
    {
      "rank": 979,
      "cve_id": "CVE-2026-106306",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in DevTools in Google Chrome prior to 155.0.8059.39 allowed a local attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106306"
    },
    {
      "rank": 980,
      "cve_id": "CVE-2026-106307",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in Network in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106307"
    },
    {
      "rank": 981,
      "cve_id": "CVE-2026-106310",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-672",
      "title": "Use of released resource in FontAccess in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106310"
    },
    {
      "rank": 982,
      "cve_id": "CVE-2026-106322",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-601",
      "title": "Open redirect in AppManifest in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106322"
    },
    {
      "rank": 983,
      "cve_id": "CVE-2026-106324",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in WebAppInstalls in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106324"
    },
    {
      "rank": 984,
      "cve_id": "CVE-2026-106326",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-441",
      "title": "Confused deputy in UI in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker to bypass system access restrictions into a privileged page via a co-installed app. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106326"
    },
    {
      "rank": 985,
      "cve_id": "CVE-2026-106327",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in Core in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106327"
    },
    {
      "rank": 986,
      "cve_id": "CVE-2026-106331",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Improper input validation in Extensions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy into a privileged page via a crafted Chrome extension. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106331"
    },
    {
      "rank": 987,
      "cve_id": "CVE-2026-106344",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106344"
    },
    {
      "rank": 988,
      "cve_id": "CVE-2026-106348",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Information leak in Animation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106348"
    },
    {
      "rank": 989,
      "cve_id": "CVE-2026-106353",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via a co-installed app. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106353"
    },
    {
      "rank": 990,
      "cve_id": "CVE-2026-106359",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-441",
      "title": "Confused deputy in DeviceBoundSessionCredentials in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106359"
    },
    {
      "rank": 991,
      "cve_id": "CVE-2026-106361",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-684",
      "title": "Incorrect provision of specified functionality in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106361"
    },
    {
      "rank": 992,
      "cve_id": "CVE-2026-106362",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in DevTools in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106362"
    },
    {
      "rank": 993,
      "cve_id": "CVE-2026-106363",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in FullScreen in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106363"
    },
    {
      "rank": 994,
      "cve_id": "CVE-2026-106365",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in Animation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106365"
    },
    {
      "rank": 995,
      "cve_id": "CVE-2026-106366",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-459",
      "title": "Incomplete cleanup in CustomTabs in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106366"
    },
    {
      "rank": 996,
      "cve_id": "CVE-2026-106367",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in Mobile in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a co-installed app. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106367"
    },
    {
      "rank": 997,
      "cve_id": "CVE-2026-106369",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in Translate in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106369"
    },
    {
      "rank": 998,
      "cve_id": "CVE-2026-106370",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-908",
      "title": "Uninitialized resource in GPU in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106370"
    },
    {
      "rank": 999,
      "cve_id": "CVE-2026-106376",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-908",
      "title": "Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106376"
    },
    {
      "rank": 1000,
      "cve_id": "CVE-2026-106381",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in Passwords in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106381"
    },
    {
      "rank": 1001,
      "cve_id": "CVE-2026-106384",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in SiteIsolation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106384"
    },
    {
      "rank": 1002,
      "cve_id": "CVE-2026-106385",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-362",
      "title": "Race condition in Chromoting in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially bypass system access restrictions via crafted network traffic. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106385"
    },
    {
      "rank": 1003,
      "cve_id": "CVE-2026-106386",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-908",
      "title": "Uninitialized resource in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106386"
    },
    {
      "rank": 1004,
      "cve_id": "CVE-2026-106389",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in USB in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106389"
    },
    {
      "rank": 1005,
      "cve_id": "CVE-2026-106395",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-908",
      "title": "Uninitialized resource in Dawn in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106395"
    },
    {
      "rank": 1006,
      "cve_id": "CVE-2026-106396",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Improper input validation in Omnibox in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106396"
    },
    {
      "rank": 1007,
      "cve_id": "CVE-2026-106397",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106397"
    },
    {
      "rank": 1008,
      "cve_id": "CVE-2026-106399",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in Skia in Google Chrome prior to 155.0.8059.39 allowed a local attacker leveraging social engineering to potentially read memory via a crafted file. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106399"
    },
    {
      "rank": 1009,
      "cve_id": "CVE-2026-106403",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in Accessibility in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106403"
    },
    {
      "rank": 1010,
      "cve_id": "CVE-2026-106404",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in FontAccess in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106404"
    },
    {
      "rank": 1011,
      "cve_id": "CVE-2026-106405",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-367",
      "title": "Race condition in CustomTabs in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker to bypass web origin policy via a co-installed app. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106405"
    },
    {
      "rank": 1012,
      "cve_id": "CVE-2026-106407",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in GetUserMedia in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106407"
    },
    {
      "rank": 1013,
      "cve_id": "CVE-2026-106408",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Protection mechanism failure in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106408"
    },
    {
      "rank": 1014,
      "cve_id": "CVE-2026-106418",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in Network in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106418"
    },
    {
      "rank": 1015,
      "cve_id": "CVE-2026-106422",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in API in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106422"
    },
    {
      "rank": 1016,
      "cve_id": "CVE-2026-106424",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Information leak in Audio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted Chrome extension. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106424"
    },
    {
      "rank": 1017,
      "cve_id": "CVE-2026-106425",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in BrowserTag in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106425"
    },
    {
      "rank": 1018,
      "cve_id": "CVE-2026-106427",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-441",
      "title": "Confused deputy in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106427"
    },
    {
      "rank": 1019,
      "cve_id": "CVE-2026-106511",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MultiversX Labs S.R.L.",
      "product": "multisig-improved",
      "cwe": null,
      "title": "CVE-2026-106511",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106511"
    },
    {
      "rank": 1020,
      "cve_id": "CVE-2026-106550",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Node-convict",
      "cwe": null,
      "title": "CVE-2026-106550",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106550"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-100372",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-100372 (MacWarrior clipbucket-v5). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-100650",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-100650 (vllm-project vllm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-100651",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-100651 (vllm-project vllm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-100652",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-100652 (vllm-project vllm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-102269",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-102269 (jpadilla pyjwt). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-102270",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-102270 (jpadilla pyjwt). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-102271",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-102271 (jpadilla pyjwt). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-102272",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-102272 (jpadilla pyjwt). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-102274",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-102274 (jpadilla pyjwt). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-102275",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-102275 (jpadilla pyjwt). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-102569",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-102569 (MacWarrior clipbucket-v5). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-102570",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-102570 (MacWarrior clipbucket-v5). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-103766",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-103766 (MacWarrior clipbucket-v5). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-104609",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-104609 (onetwothreeneth HospitalManagementSystem). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-104612",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-104612 (SourceCodester Student Result Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-104625",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-104625 (CodeAstro Simple Loan Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-104982",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-104982 (Linux Mint Xreader). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-105098",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-105098 (Omega Solution CoinEx Crypto). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-105135",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-105135 (InternLM MindSearch). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-105145",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-105145 (Weaviate Verba). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-105166",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-105166 (kishor-23 food-waste-management-system). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-105170",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-105170 (kishor-23 food-waste-management-system). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-105174",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-105174 (Gerapy). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-105182",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-105182 (SourceCodester Online Reviewer Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-105186",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-105186 (itsourcecode Online Admission System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-105314",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-105314 (Papermerge). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-105383",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-105383 (onetwothreeneth HospitalManagementSystem). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-105386",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-105386 (onetwothreeneth HospitalManagementSystem). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-105387",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-105387 (girishsaraf Online-Appointment-Booking-System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-105388",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-105388 (feelec-yishu feelcrm-os). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-105392",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-105392 (Lybbn Django-Vue-Lyadmin). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-105438",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-105438 (O2OA). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-105469",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-105469 (girishsaraf Online-Appointment-Booking-System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-105470",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-105470 (girishsaraf Online-Appointment-Booking-System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-105643",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-105643 (TryGhost Ghost). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19856",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19856 (Unknown All in One SEO). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58010",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58010 (GNOME GLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58012",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58012 (GNOME GLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58013",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58013 (GNOME GLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58014",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58014 (GNOME GLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58015",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58015 (GNOME GLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59870",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59870 (nodeca js-yaml). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67421",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67421 (rabbitmq-server). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73547",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73547 (envoyproxy envoy). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-95812",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-95812 (MacWarrior clipbucket-v5). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-96272",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-96272 (MacWarrior clipbucket-v5). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-96421",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-96421 (Wireshark Foundation Wireshark). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-96422",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-96422 (Wireshark Foundation Wireshark). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-96423",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-96423 (Wireshark Foundation Wireshark). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-97062",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-97062 (Webkul Aureus ERP). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-102489",
      "detail": "DUE DATE PASSED — CVE-2026-102489 (Zammad GmbH Zammad). CISA remediation deadline was October 5, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-102490",
      "detail": "DUE DATE PASSED — CVE-2026-102490 (Zammad GmbH Zammad). CISA remediation deadline was October 5, 2026; still in catalog."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-102269",
      "detail": "RESCORED — CVE-2026-102269 (jpadilla pyjwt). CVSS 4.8 → 5.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-102270",
      "detail": "RESCORED — CVE-2026-102270 (jpadilla pyjwt). CVSS 4.4 → 4.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-102274",
      "detail": "RESCORED — CVE-2026-102274 (jpadilla pyjwt). CVSS 5.9 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-102275",
      "detail": "RESCORED — CVE-2026-102275 (jpadilla pyjwt). CVSS 6.5 → 8.2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-105471",
      "detail": "RESCORED — CVE-2026-105471 (girishsaraf Online-Appointment-Booking-System). CVSS 6.9 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16335",
      "detail": "RESCORED — CVE-2026-16335 (IBM DataStage on Cloud Pak for Data). CVSS 8.1 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16338",
      "detail": "RESCORED — CVE-2026-16338 (IBM DataStage on Cloud Pak for Data). CVSS 9.9 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16432",
      "detail": "RESCORED — CVE-2026-16432 (IBM DataStage on Cloud Pak for Data). CVSS 7.7 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-25255",
      "detail": "RESCORED — CVE-2026-25255 (Qualcomm, Inc. Snapdragon). CVSS 8.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-25262",
      "detail": "RESCORED — CVE-2026-25262 (Qualcomm, Inc. Snapdragon). CVSS 6.9 → 6.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-66269",
      "detail": "RESCORED — CVE-2026-66269 (Dell OpenManage Server Administrator Managed Node (Patch) for Windows). CVSS 7.3 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-70341",
      "detail": "RESCORED — CVE-2026-70341 (Microsoft Edge (Chromium-based)). CVSS 8.5 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-7700",
      "detail": "RESCORED — CVE-2026-7700 (langflow-ai langflow). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-80423",
      "detail": "RESCORED — CVE-2026-80423 (IBM DataStage on Cloud Pak for Data). CVSS 8.8 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-80442",
      "detail": "RESCORED — CVE-2026-80442 (IBM Guardium Data Protection). CVSS 9.9 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-81478",
      "detail": "RESCORED — CVE-2026-81478 (Dell OpenManage Server Administrator Managed Node (Patch) for Windows). CVSS 8.1 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-81549",
      "detail": "RESCORED — CVE-2026-81549 (IBM DataStage on Cloud Pak for Data). CVSS 9.6 → 7.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-81623",
      "detail": "RESCORED — CVE-2026-81623 (IBM Guardium Data Protection). CVSS 6.3 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-96420",
      "detail": "RESCORED — CVE-2026-96420 (Wireshark Foundation Wireshark). CVSS 4.7 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-96423",
      "detail": "RESCORED — CVE-2026-96423 (Wireshark Foundation Wireshark). CVSS 5.5 → 7.1 (NVD)."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2025-62973",
      "detail": "PATCH SHIPPED — CVE-2025-62973 (Themekraft BuddyForms). Fixed in BuddyForms 2.10.4."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-42418",
      "detail": "PATCH SHIPPED — CVE-2026-42418 (Socialrocket Social Rocket). Fixed in Social Rocket 1.3.6."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-42638",
      "detail": "PATCH SHIPPED — CVE-2026-42638 (Awesomemotive Easy Digital Downloads). Fixed in Easy Digital Downloads 3.7.1.1."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-81792",
      "detail": "PATCH SHIPPED — CVE-2026-81792 (MultiVendorX Product Catalog Enquiry for WooCommerce by MultiVendorX). Fixed in Product Catalog Enquiry for WooCommerce by MultiVendorX 6.1.6."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64040",
      "detail": "ENRICHED — CVE-2026-64040 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-98049",
      "detail": "ENRICHED — CVE-2026-98049 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-98051",
      "detail": "ENRICHED — CVE-2026-98051 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-98053",
      "detail": "ENRICHED — CVE-2026-98053 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-98054",
      "detail": "ENRICHED — CVE-2026-98054 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-98080",
      "detail": "ENRICHED — CVE-2026-98080 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-98082",
      "detail": "ENRICHED — CVE-2026-98082 (Linux). Received CVSS 5.5 and CPE data from NVD."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
