{
  "day": "2026-10-07",
  "boundary": "UTC calendar day",
  "published_count": 330,
  "by_severity": {
    "CRITICAL": 47,
    "HIGH": 110,
    "MEDIUM": 149,
    "LOW": 9
  },
  "kev_count": 0,
  "exploit_reference_count": 0,
  "awaiting_enrichment_count": 15,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-88962",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00789,
      "epss_percentile": 0.54856,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-94",
      "title": "Langflow OSS is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88962"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-93674",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00756,
      "epss_percentile": 0.5374,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-94",
      "title": "Langflow OSS is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93674"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-93675",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00678,
      "epss_percentile": 0.50795,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-440",
      "title": "Langflow OSS is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93675"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-105192",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00671,
      "epss_percentile": 0.50454,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LMCache",
      "product": "LMCache",
      "cwe": "CWE-306",
      "title": "LMCache Unauthenticated RCE in multiprocess mode via pickle deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105192"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-105324",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00653,
      "epss_percentile": 0.49674,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ASUSTOR Inc.",
      "product": "ADM",
      "cwe": "CWE-113",
      "title": "An HTTP header injection vulnerability was found in the ADM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105324"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-93448",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0064,
      "epss_percentile": 0.4905,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-22",
      "title": "Langflow OSS is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93448"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-93445",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0061,
      "epss_percentile": 0.47547,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-94",
      "title": "Langflow OSS is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93445"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-93449",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00582,
      "epss_percentile": 0.46074,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-94",
      "title": "Langflow OSS is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93449"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-93443",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00582,
      "epss_percentile": 0.46074,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-94",
      "title": "Langflow OSS is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93443"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-93679",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00469,
      "epss_percentile": 0.386,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-400",
      "title": "Langflow OSS is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93679"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-93677",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0046,
      "epss_percentile": 0.37815,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-200",
      "title": "Langflow OSS is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93677"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-92393",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00452,
      "epss_percentile": 0.37211,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache YuniKorn",
      "cwe": "CWE-863",
      "title": "Apache YuniKorn: Admission control bypass via workload UPDATE operation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92393"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-97671",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00446,
      "epss_percentile": 0.36777,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-22",
      "title": "Langflow OSS is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97671"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-97673",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.35788,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-693",
      "title": "Langflow OSS is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97673"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-93447",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00429,
      "epss_percentile": 0.35129,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-502",
      "title": "Langflow OSS is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93447"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-107104",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00423,
      "epss_percentile": 0.34559,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Manacle Technologies",
      "product": "Multi-tenant ERP System",
      "cwe": "CWE-502",
      "title": "Unsafe Deserialization Vulnerability in Manacle Technologies ERP System",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107104"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-42720",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00383,
      "epss_percentile": 0.30189,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sarah Giles",
      "product": "Dynamic User Directory",
      "cwe": "CWE-89",
      "title": "WordPress Dynamic User Directory plugin <= 2.4 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42720"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-42721",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00383,
      "epss_percentile": 0.3019,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SERVIT Software Solutions",
      "product": "affiliate-toolkit",
      "cwe": "CWE-89",
      "title": "WordPress affiliate-toolkit plugin <= 3.9.1 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42721"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-93678",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00382,
      "epss_percentile": 0.30062,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-639",
      "title": "Langflow OSS is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93678"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-97188",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00375,
      "epss_percentile": 0.29329,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "String locator",
      "cwe": "CWE-502",
      "title": "String Locator < 2.6.8 - Unauthenticated PHP Object Injection via Database Editor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97188"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-19572",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00372,
      "epss_percentile": 0.28993,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Flexera",
      "product": "FlexNet Publisher",
      "cwe": "CWE-288",
      "title": "FlexNet Publisher lmadmin SOAP Authentication Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19572"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-58069",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.28847,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Veeam",
      "product": "Backup and Replication",
      "cwe": "CWE-22",
      "title": "This vulnerability in Veeam Backup & Replication allows an authenticated Cloud Connect tenant to read arbitrary files on the service provider host.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58069"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-104677",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.28791,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Coder",
      "cwe": "CWE-94",
      "title": "WP Coder 4.0 - 4.5.1 - Editor+ RCE via Global PHP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104677"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-102173",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00366,
      "epss_percentile": 0.28367,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themeum",
      "product": "Kirki – Freeform Page Builder, Website Builder & Customizer",
      "cwe": "CWE-79",
      "title": "Kirki – Freeform Page Builder, Website Builder & Customizer <= 6.3.1 - Unauthenticated Stored Cross-Site Scripting via Registration Metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102173"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-97146",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00366,
      "epss_percentile": 0.28348,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache YuniKorn",
      "cwe": "CWE-290",
      "title": "Apache YuniKorn: Admission control bypass via system label forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97146"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2025-64393",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0036,
      "epss_percentile": 0.27681,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Veeam",
      "product": "Backup and Replication",
      "cwe": "CWE-502",
      "title": "This vulnerability in Veeam Backup & Replication allows a Backup Viewer to execute arbitrary code as SYSTEM on the backup server.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-64393"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2025-64392",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00338,
      "epss_percentile": 0.25143,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Veeam",
      "product": "Backup Enterprise Manager",
      "cwe": "CWE-79",
      "title": "This vulnerability in Veeam Backup Enterprise Manager allows an attacker to execute script in the browser of a portal user who opens a crafted link.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-64392"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-83540",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.2502,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wolfSSL",
      "product": "wolfSSH",
      "cwe": "CWE-287",
      "title": "wolfSSHd on Windows race condition leading to logon token reused across connections",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83540"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-83742",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0033,
      "epss_percentile": 0.24055,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wolfSSL Inc.",
      "product": "wolfSSH",
      "cwe": "CWE-121",
      "title": "wstrncat() unsigned integer underflow leads to an off-by-one null write in wolfSSH on non-Windows platforms",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83742"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-107103",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00325,
      "epss_percentile": 0.23589,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Manacle Technologies",
      "product": "Multi-tenant ERP System",
      "cwe": "CWE-89",
      "title": "SQL Injection Vulnerability in Manacle Technologies ERP System",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107103"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-14911",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00319,
      "epss_percentile": 0.22839,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ASUS",
      "product": "Router",
      "cwe": "CWE-79",
      "title": "Improper Neutralization of Input During Web Page Generation (“Cross-site Scripting”) in ASUS router modules allows a remote attacker to read DOM information, modify router settings, and cause a denial-of-service condition when an authenticated user visits a crafted URL.Refer to the ' Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14911"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-15894",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00307,
      "epss_percentile": 0.21565,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-121",
      "title": "Bluetooth Mesh solicitation PDU stack buffer overflow via oversized advertisement",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15894"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-84897",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00301,
      "epss_percentile": 0.20939,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wolfSSL Inc.",
      "product": "wolfSSH",
      "cwe": "CWE-372",
      "title": "wolfSSH server accepts server-to-client DH group exchange messages from an unauthenticated client, causing pre-authentication primality-test CPU exhaustion and key exchange role confusion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84897"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-93026",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00299,
      "epss_percentile": 0.20673,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Veeam",
      "product": "Backup and Replication",
      "cwe": "CWE-862",
      "title": "This vulnerability in Veeam Backup & Replication allows a Backup Viewer to modify the Enterprise Manager master key and stored antivirus update credentials.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93026"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-102478",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00295,
      "epss_percentile": 0.20329,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Octopus Deploy",
      "product": "Octopus Server",
      "cwe": "CWE-1289",
      "title": "In affected versions of Octopus Server, an authenticated user with permission to modify roles could bypass the protections preventing access abuse resulting in privilege escalation. It was possible for the built-in role to be weakened and the attacker's account added to a privileged team. This was achievable due to improper validation of unsafe equivalence in inputs.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102478"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-27434",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00294,
      "epss_percentile": 0.20138,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sc Internet Vivoo",
      "product": "WP Rentals",
      "cwe": "CWE-862",
      "title": "WordPress WP Rentals theme <= 3.14.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27434"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-5703",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00292,
      "epss_percentile": 0.19933,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Satel Iberia",
      "product": "SenNet Datalogger Serie 200",
      "cwe": "CWE-35",
      "title": "Path Traversal in Satel Iberia SenNet Datalogger Serie 200",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5703"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-106471",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.18555,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Satellite 6",
      "cwe": "CWE-863",
      "title": "Candlepin: candlepin: broken object-level authorization via verifyauthorizationfilter multi-@verify hasaccess latching",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106471"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-102782",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00277,
      "epss_percentile": 0.18456,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ordasoft.com",
      "product": "OrdaSoft Simple Membership extension for Joomla",
      "cwe": "CWE-89",
      "title": "Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Simple Membership < 7.4.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102782"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-81535",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00276,
      "epss_percentile": 0.18371,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wolfSSL Inc.",
      "product": "wolfSSH",
      "cwe": "CWE-862",
      "title": "wolfSSH SSH client accepts unsolicited forwarded-tcpip channel opens without an authorization check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81535"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-103075",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00259,
      "epss_percentile": 0.16097,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPMU DEV",
      "product": "Hustle",
      "cwe": "CWE-862",
      "title": "WordPress Hustle plugin <= 7.8.14.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103075"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-59346",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00258,
      "epss_percentile": 0.16005,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VMware",
      "product": "VMware Workstation",
      "cwe": "CWE-190",
      "title": "VMware Workstation and Fusion VMXNET3 integer-overflow vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59346"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-107102",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00255,
      "epss_percentile": 0.15702,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Manacle Technologies",
      "product": "Multi-tenant ERP System",
      "cwe": "CWE-345",
      "title": "Account Takeover Vulnerability in Manacle Technologies ERP System",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107102"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-78243",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00251,
      "epss_percentile": 0.15055,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache YuniKorn",
      "cwe": "CWE-248",
      "title": "Apache YuniKorn: LDAP Group provider panics on lowercase attribute name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78243"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-89417",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00247,
      "epss_percentile": 0.14614,
      "kev": false,
      "kev_due_at": null,
      "vendor": "daanvandenbergh",
      "product": "OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy.",
      "cwe": "CWE-79",
      "title": "OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. <= 6.3.10 - Unauthenticated Stored Cross-Site Scripting via 's' Search Parameter in comments-atom Feed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89417"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-105876",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00246,
      "epss_percentile": 0.14531,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Chill",
      "product": "Modula Image Gallery",
      "cwe": "CWE-862",
      "title": "WordPress Modula Image Gallery plugin <= 3.0.11 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105876"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-102781",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00239,
      "epss_percentile": 0.13785,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ordasoft.com",
      "product": "Touch Slider extension for Joomla",
      "cwe": "CWE-284",
      "title": "Joomla Extension - ordasoft.com - Unauthenticated Destructive CRUD in OrdaSoft Touch Slider < 5.4.6",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102781"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-104652",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.13307,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Envira Gallery",
      "cwe": "CWE-79",
      "title": "Envira Gallery < 1.16.1 - Author+ Stored XSS via Gallery Image ID",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104652"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-104653",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.13307,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Envira Gallery",
      "cwe": "CWE-79",
      "title": "Envira Gallery < 1.16.1 - Author+ Stored XSS via Gallery Crop Dimensions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104653"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-103870",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00233,
      "epss_percentile": 0.12966,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Satellite 6",
      "cwe": "CWE-22",
      "title": "Pulp-rpm: distribution tree publish creates directories from .treeinfo ids",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103870"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-87782",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00232,
      "epss_percentile": 0.12895,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Koinonia Link",
      "cwe": "CWE-269",
      "title": "Koinonia Link 1.1.2 - 1.1.4 - Subscriber+ Privilege Escalation to Administrator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87782"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-86816",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00232,
      "epss_percentile": 0.12938,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WPCafe",
      "cwe": "CWE-200",
      "title": "WPCafe < 3.0.21 - Unauthenticated Product Data Disclosure via REST API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86816"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-104667",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.12745,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Animated Number Counters",
      "cwe": "CWE-89",
      "title": "Animated Number Counters < 3.1 - Editor+ Second-Order SQLi via Counter Order",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104667"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-104953",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.12745,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MPG",
      "cwe": "CWE-89",
      "title": "MPG < 4.2.3 - Editor+ SQLi via Project Import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104953"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-103868",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00227,
      "epss_percentile": 0.1238,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2",
      "cwe": "CWE-488",
      "title": "Pulp-container: registry credentials are reused across remotes in a worker",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103868"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-103869",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00227,
      "epss_percentile": 0.1238,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2",
      "cwe": "CWE-488",
      "title": "Pulp-ansible: bearer tokens are reused across remotes in a worker",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103869"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-97294",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00224,
      "epss_percentile": 0.11999,
      "kev": false,
      "kev_due_at": null,
      "vendor": "David Lingren",
      "product": "Media LIbrary Assistant",
      "cwe": "CWE-79",
      "title": "WordPress Media LIbrary Assistant plugin <= 3.41 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97294"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-104391",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00224,
      "epss_percentile": 0.11989,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ExpressTech",
      "product": "Quiz And Survey Master",
      "cwe": "CWE-79",
      "title": "WordPress Quiz And Survey Master plugin <= 11.2.7 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104391"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-104393",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00224,
      "epss_percentile": 0.1199,
      "kev": false,
      "kev_due_at": null,
      "vendor": "weDevs",
      "product": "Happy Addons for Elementor",
      "cwe": "CWE-79",
      "title": "WordPress Happy Addons for Elementor plugin <= 3.50.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104393"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-105884",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00224,
      "epss_percentile": 0.12008,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Media",
      "product": "Rocket Lazy Load",
      "cwe": "CWE-79",
      "title": "WordPress Rocket Lazy Load plugin <= 2.4.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105884"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-96530",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00219,
      "epss_percentile": 0.11292,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Optimole",
      "cwe": "CWE-200",
      "title": "Optimole 4.0.0 - 4.2.14 - Subscriber+ Sensitive Data Disclosure via Dashboard Widget",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96530"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-104390",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00213,
      "epss_percentile": 0.10602,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arraytics",
      "product": "Booktics",
      "cwe": "CWE-862",
      "title": "WordPress Booktics plugin <= 1.0.27 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104390"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-19186",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00212,
      "epss_percentile": 0.10581,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-191",
      "title": "Integer underflow in IEEE 802.15.4 frame decryption leads to out-of-bounds read and write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19186"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-105871",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.10467,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BdThemes",
      "product": "Element Pack Elementor Addons",
      "cwe": "CWE-79",
      "title": "WordPress Element Pack Elementor Addons plugin <= 8.8.6 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105871"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-105873",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.10467,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BdThemes",
      "product": "Element Pack Elementor Addons",
      "cwe": "CWE-79",
      "title": "WordPress Element Pack Elementor Addons plugin <= 8.8.6 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105873"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-105875",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.10466,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BdThemes",
      "product": "Prime Slider – Addons For Elementor",
      "cwe": "CWE-79",
      "title": "WordPress Prime Slider – Addons For Elementor plugin <= 4.6.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105875"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-103416",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00209,
      "epss_percentile": 0.10205,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse ThreadX - NetX Duo",
      "cwe": "CWE-787",
      "title": "Out-of-bounds write via the TLS 1.3 handshake message cache in NetX Duo in Eclipse ThreadX NetX Duo 6.5.1.202602 allows a handshake message larger than the cache writes past it and on into the rest of the session control block, which holds pointers. A malicious or compromised server can make a TLS 1.3 client produce such a message before certificate authentication completes, so no server certificate is needed to reach it.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103416"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-16528",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00207,
      "epss_percentile": 0.09878,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ASUS",
      "product": "Router",
      "cwe": "CWE-532",
      "title": "Insertion of Sensitive Information into Log File in certain ASUS router models allows a remote authenticated attacker to obtain DDNS credentials from the system log, potentially enabling modification of DNS settings.Refer to the ' Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16528"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-59347",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00207,
      "epss_percentile": 0.09914,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VMware",
      "product": "VMware Workstation",
      "cwe": "CWE-121",
      "title": "VMware Workstation and Fusion HGFS stack-based buffer-overflow vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59347"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-97720",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00196,
      "epss_percentile": 0.08526,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Impala",
      "cwe": "CWE-303",
      "title": "Apache Impala: Impala Executor Webserver Auth Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97720"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-90466",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00196,
      "epss_percentile": 0.08505,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Impala",
      "cwe": "CWE-23",
      "title": "Apache Impala: Path traversal executes JARs outside trusted paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90466"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-105322",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.08302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Magee Shortcodes",
      "cwe": "CWE-472",
      "title": "Magee Shortcodes <= 2.1.1 - Unauthenticated Mail Relay via Contact Form",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105322"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-19386",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00192,
      "epss_percentile": 0.08121,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ASUS",
      "product": "Router",
      "cwe": "CWE-121",
      "title": "A stack-based buffer overflow in the ASUS router modules allows an authenticated nearby user to execute arbitrary code via a crafted configuration file upload that exceeds the expected buffer size.Refer to the ' Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19386"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-82211",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00187,
      "epss_percentile": 0.07607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Nexi XPay Build",
      "cwe": "CWE-862",
      "title": "Nexi XPay Build <= 7.6.2 - Unauthenticated Payment Completion and Order Key Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82211"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-93684",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00186,
      "epss_percentile": 0.07553,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Impala",
      "cwe": "CWE-79",
      "title": "Apache Impala: Stored XSS in Impala query plans",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93684"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-97354",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00179,
      "epss_percentile": 0.06824,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "PowerPress Podcasting plugin by Blubrry",
      "cwe": "CWE-918",
      "title": "PowerPress 11.13.12 - 11.17.9 - Contributor+ SSRF via Media URL Redirects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97354"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-97331",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.06572,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "User Private Files",
      "cwe": "CWE-200",
      "title": "User Private Files < 2.1.9 - Subscriber+ User Email Address Disclosure via dpk_upvf_rmv_access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97331"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-104678",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00168,
      "epss_percentile": 0.05588,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "CP Media Player",
      "cwe": "CWE-284",
      "title": "CP Media Player < 1.3.4 - Contributor+ Media Player Settings Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104678"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-105316",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00164,
      "epss_percentile": 0.05072,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Magee Shortcodes",
      "cwe": "CWE-79",
      "title": "Magee Shortcodes <= 2.1.1 - Reflected XSS via live_preview and magee_create_shortcode Actions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105316"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-86833",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.04842,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MetForm",
      "cwe": "CWE-74",
      "title": "MetForm < 4.3.1 - Unauthenticated HTML Injection in Notification Emails via Field Shortcodes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86833"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-16516",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0015,
      "epss_percentile": 0.03649,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wolfSSL Inc.",
      "product": "wolfSSH",
      "cwe": "CWE-345",
      "title": "wolfSSH ECDSA host key curve not validated against negotiated algorithm",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16516"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-87971",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.03331,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "If-So Dynamic Content",
      "cwe": "CWE-79",
      "title": "If-So Dynamic Content 1.4.4 - 1.10.1 - Reflected XSS via 'message' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87971"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-103378",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.03289,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Geliver Akıllı Kargo Pazaryeri",
      "cwe": "CWE-200",
      "title": "Geliver Akıllı Kargo Pazaryeri 3.0.0 - 3.1.0 - Unauthenticated API Key Disclosure via Public Log File",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103378"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-103323",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.02608,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Integration for Epos Now and WooCommerce",
      "cwe": "CWE-862",
      "title": "Integration for Epos Now and WooCommerce 4.6.0 - 4.11.1 - Unauthenticated Action Scheduler Queue Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103323"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-103681",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.02371,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Frontend Dashboard",
      "cwe": "CWE-284",
      "title": "Frontend Dashboard < 3.0.0 - Subscriber+ Profile and Post Field Deletion via fed_user_profile_delete",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103681"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-104049",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.02371,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Academy LMS",
      "cwe": "CWE-639",
      "title": "Academy LMS < 4.0.0 - Subscriber+ Arbitrary Lesson Content Disclosure via Topic REST Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104049"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-104050",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.02372,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Academy LMS",
      "cwe": "CWE-639",
      "title": "Academy LMS < 4.0.0 - Subscriber+ Cross-Course Quiz Answer Disclosure via render_quiz_answers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104050"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-104651",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.02371,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Yaad Sarig Payment Gateway For WC",
      "cwe": "CWE-639",
      "title": "Yaad Sarig Payment Gateway For WC < 2.2.13 - Subscriber+ Arbitrary Order Payment Manipulation via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104651"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-82212",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00131,
      "epss_percentile": 0.02322,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Nexi XPay Build",
      "cwe": "CWE-345",
      "title": "Nexi XPay Build <= 7.6.2 - Unauthenticated Payment Bypass via NPG Notification Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82212"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-19396",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.02062,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ASUS",
      "product": "Router",
      "cwe": "CWE-337",
      "title": "A predictable seed in the pseudo-random number generator (PRNG) in the IFTTT pairing token generation of the ASUS RT-BE57 router allows an unauthenticated nearby user to derive the pairing token and read or modify router settings via observed values from an administrator-initiated IFTTT pairing session.Refer to the ' Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19396"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2025-64391",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00116,
      "epss_percentile": 0.01482,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Veeam",
      "product": "Agent for Windows",
      "cwe": "CWE-1386",
      "title": "This vulnerability in Veeam Agent for Microsoft Windows allows a low-privileged local user to make the agent write files to arbitrary locations when an administrator installs it.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-64391"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-106061",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00105,
      "epss_percentile": 0.0099,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-125",
      "title": "Gimp: gimp: heap buffer over-read in x cursor (xmc) thumbnail loader on crafted file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106061"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-58068",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00101,
      "epss_percentile": 0.00841,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Veeam",
      "product": "Agent for Windows",
      "cwe": "CWE-862",
      "title": "This vulnerability in Veeam Agent for Microsoft Windows allows any local user to terminate arbitrary processes on the system.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58068"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-107121",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00084,
      "epss_percentile": 0.00245,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-319",
      "title": "Keycloak-services: keycloak-services: smtp starttls plaintext credential and message downgrade",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107121"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2025-70518",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-77",
      "title": "The management portal's diagnostic ping tool of Fanvil x7a firmware version 2.6.0.1182 does not handle user supplied input securely. The lack of secure user input handling allows any unauthenticated attacker to inject commands and run code in the underlying Android operating system.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-70518"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-76482",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco License On-Prem",
      "cwe": "CWE-347",
      "title": "Cisco License On-Prem Security Hardening Release",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76482"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-102255",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SonicWall",
      "product": "SMA1000",
      "cwe": "CWE-441",
      "title": "A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102255"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2025-70521",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-77",
      "title": "The management portal's diagnostic ping tool of Fanvil x7a firmware version 2.6.0.1182 does not handle user supplied input securely. The lack of secure user input handling allows any unauthenticated attacker to inject commands and run code in the underlying Android operating system.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-70521"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-62252",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sipcapture",
      "product": "homer",
      "cwe": "CWE-798",
      "title": "Homer: Hardcoded Default Admin Password 'sipcapture' With No Forced Change on First Login",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62252"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-62253",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sipcapture",
      "product": "homer",
      "cwe": "CWE-306",
      "title": "Homer: Complete Authentication Bypass When coordinator.jwt.secret Is Empty (Default)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62253"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-76268",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-306",
      "title": "Missing Authentication for Critical Function in the Patroni REST API in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76268"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-76455",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco NX-OS Software",
      "cwe": "CWE-284",
      "title": "Cisco NX-OS Software Security Hardening Release: October 2026 - Improper Access Control Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76455"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-76465",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco NX-OS Software",
      "cwe": "CWE-590",
      "title": "Cisco Nexus 3000 and 9000 Series Switches MPLS OAM Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76465"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-76471",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco NX-OS Software",
      "cwe": "CWE-122",
      "title": "Cisco NX-OS Software NX-API Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76471"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-76480",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco License On-Prem",
      "cwe": "CWE-306",
      "title": "Cisco License On-Prem Security Hardening Release",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76480"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-76485",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco NX-OS Software",
      "cwe": "CWE-121",
      "title": "Cisco Nexus 3000 and 9000 Series Switches VXLAN OAM (NGOAM) Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76485"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-76486",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco NX-OS Software",
      "cwe": "CWE-121",
      "title": "Cisco Nexus 3000 and 9000 Series Switches VXLAN OAM (NGOAM) Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76486"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-76498",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Application Policy Infrastructure Controller (APIC)",
      "cwe": "CWE-284",
      "title": "Cisco Application Policy Infrastructure Controller Hardening Release: October 2026 - Improper Access Control Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76498"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-76499",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Application Policy Infrastructure Controller (APIC)",
      "cwe": "CWE-707",
      "title": "Cisco Application Policy Infrastructure Controller Hardening Release: October 2026 - Improper Neutralization Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76499"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-76500",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Application Policy Infrastructure Controller (APIC)",
      "cwe": "CWE-664",
      "title": "Cisco Application Policy Infrastructure Controller Hardening Release: October 2026 - Improper Control of a Resource Through its Lifetime Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76500"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-76501",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco NX-OS Software",
      "cwe": "CWE-121",
      "title": "Cisco Nexus 9000 Series Switches SRv6 OAM (NGOAM) Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76501"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-95606",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Liquid Web / StellarWP",
      "product": "The Events Calendar",
      "cwe": "CWE-502",
      "title": "WordPress The Events Calendar plugin <= 6.17.4 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95606"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-76464",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Campus Gateway Software",
      "cwe": "CWE-119",
      "title": "Cisco Meraki Hardening Release October 2026 - Buffer Management Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76464"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-107282",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AsyncHttpClient",
      "product": "async-http-client",
      "cwe": "CWE-319",
      "title": "AsyncHttpClient: Replay to a different host sends the original host request and credentials to the new host",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107282"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-92414",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Jackrabbit",
      "cwe": "CWE-384",
      "title": "Apache Jackrabbit: Pre-auth hijack of cached sessions via derivable WebDAV lock tokens",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92414"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-95605",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Passionate Programmer Peter",
      "product": "WP Data Access",
      "cwe": "CWE-89",
      "title": "WordPress WP Data Access plugin <= 5.5.82 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95605"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-96408",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Six Apart Ltd.",
      "product": "Movable Type Cloud Edition",
      "cwe": "CWE-94",
      "title": "A code injection vulnerability exists in the upgrade script of Movable Type, which may allow an unauthenticated attacker to execute an arbitrary Perl script or an SQL query on the affected product.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96408"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-107204",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LMCache",
      "product": "LMCache",
      "cwe": "CWE-306",
      "title": "LMCache through 0.5.5 Unauthenticated RCE via /run_script Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107204"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-107183",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ggml-org",
      "product": "llama.cpp",
      "cwe": "CWE-416",
      "title": "llama.cpp before b11393 Use-After-Free via common_chat_peg_mapper chat_parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107183"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-107194",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sungrow",
      "product": "iSolarCloud",
      "cwe": "CWE-288",
      "title": "Sungrow iSolarCloud before 2026 allows authentication bypass and account takeover via \"login_type\":\"5\" in a login request, potentially leading to \"local blackouts on the whole continent\" in Europe. An email address for the user_account property is required; however, a user can view the email address associated with their parent organization.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107194"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2025-70516",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-306",
      "title": "The websocket handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce proper authentication restrictions against sessionless users. The lack of restrictions grants anyone the ability to view any device resources such as operational logs or perform diagnostic requests.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-70516"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-20328",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco License On-Prem",
      "cwe": "CWE-862",
      "title": "Cisco Smart Software Manager On-Prem Arbitrary Account Password Reset Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20328"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-62176",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-94",
      "title": "PraisonAI: Code Injection via f-string Interpolation in Deploy API Server Generation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62176"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-76454",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco License On-Prem",
      "cwe": "CWE-23",
      "title": "Cisco Smart Software Manager On-Prem Unauthenticated API Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76454"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-76483",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco License On-Prem",
      "cwe": "CWE-522",
      "title": "Cisco License On-Prem Security Hardening Release",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76483"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-107202",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jonssonyan",
      "product": "h-ui",
      "cwe": "CWE-77",
      "title": "CVE-2026-107202",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107202"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-76453",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco NX-OS Software",
      "cwe": "CWE-707",
      "title": "Cisco NX-OS Software Security Hardening Release: October 2026 - Improper Neutralization Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76453"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-76459",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco NX-OS Software",
      "cwe": "CWE-787",
      "title": "Cisco NX-OS Software Security Hardening Release: October 2026 - Out-of-bounds Write Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76459"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-76463",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Campus Gateway Software",
      "cwe": "CWE-284",
      "title": "Cisco Meraki Security Hardening Release: October 2026 - Improper Access Control Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76463"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-76470",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Campus Gateway Software",
      "cwe": "CWE-682",
      "title": "Cisco Meraki Hardening Release - Incorrect Calculation Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76470"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-76472",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Campus Gateway Software",
      "cwe": "CWE-74",
      "title": "Cisco Meraki Security Hardening Release October 2026 - Improper Neutralization of Special Elements Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76472"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-76484",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco License On-Prem",
      "cwe": "CWE-94",
      "title": "Cisco License On-Prem Security Hardening Release",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76484"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-95534",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unlimited Elements",
      "product": "Unlimited Elements For Elementor (Free Widgets, Addons, Templates)",
      "cwe": "CWE-502",
      "title": "WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.19 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95534"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-103668",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Six Apart Ltd.",
      "product": "Movable Type Cloud Edition",
      "cwe": "CWE-89",
      "title": "An SQL Injection vulnerability exists in the Site Search function of Movable Type, which may allow an unauthenticated attacker to execute an arbitrary SQL query on the affected product.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103668"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-106558",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "backstage",
      "product": "backstage",
      "cwe": "CWE-502",
      "title": "Backstage: Improper validation of TechDocs MkDocs configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106558"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-107205",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LMCache",
      "product": "LMCache",
      "cwe": "CWE-306",
      "title": "LMCache through 0.5.5 Missing Authentication in MP Coordinator Fleet Control API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107205"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-107206",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LMCache",
      "product": "LMCache",
      "cwe": "CWE-306",
      "title": "LMCache through 0.5.5 Missing Authentication in MP HTTP Server Management API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107206"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-107279",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AsyncHttpClient",
      "product": "async-http-client",
      "cwe": "CWE-303",
      "title": "AsyncHttpClient: Digest mutual authentication is switched off by a peer offering qop=auth-int",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107279"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-97716",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Absolute Security",
      "product": "Secure Access",
      "cwe": "CWE-400",
      "title": "Denial of Service in Absolute Secure Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97716"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-106059",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gitahead",
      "product": "gitahead",
      "cwe": "CWE-78",
      "title": "GitAhead through 2.7.1 on macOS Command Injection via Show in Finder AppleScript",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106059"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-107211",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "qax-os",
      "product": "excelize",
      "cwe": "CWE-129",
      "title": "Excelize: Unchecked pivot-cache field index in extractPivotTableFields causes unrecoverable panic",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107211"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-107213",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "qax-os",
      "product": "excelize",
      "cwe": "CWE-476",
      "title": "Excelize: Nil-pointer dereference in GetSlicers when a worksheet has extLst present but no drawing element",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107213"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-107231",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AsyncHttpClient",
      "product": "async-http-client",
      "cwe": "CWE-319",
      "title": "AsyncHttpClient: Digest challenge without a usable nonce downgrades to Basic and sends the password in cleartext",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107231"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-76456",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco NX-OS Software",
      "cwe": "CWE-20",
      "title": "Cisco NX-OS Software Security Hardening Release: October 2026 - Improper Input Validation Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76456"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-76457",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco NX-OS Software",
      "cwe": "CWE-125",
      "title": "Cisco NX-OS Software Security Hardening Release: October 2026 - Out-of-bounds Read Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76457"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-76458",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco NX-OS Software",
      "cwe": "CWE-703",
      "title": "Cisco NX-OS Software Security Hardening Release: October 2026 - Improper Handling of Exceptional Conditions Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76458"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-107181",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Telegram",
      "product": "Telegram Desktop",
      "cwe": "CWE-143",
      "title": "Telegram Desktop before 7.2.9 IPC Record Injection File Exfiltration via interpret: Scheme",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107181"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-34499",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Johnson Controls",
      "product": "ADVMS",
      "cwe": "CWE-321",
      "title": "Use of hard-coded cryptographic key vulnerability in Johnson Controls ADVMS allows Read Sensitive Constants Within an Executable. This issue affects ADVMS: before 3.10.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34499"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-106057",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wummel",
      "product": "patool",
      "cwe": "CWE-78",
      "title": "patool before 4.0.6 OS Command Injection on Windows via shell_quote_nt",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106057"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-77214",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libexpat",
      "product": "libexpat",
      "cwe": "CWE-125",
      "title": "libexpat Heap Buffer Over-read in xmlparse.c via XML_ParseBuffer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77214"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-76468",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Campus Gateway Software",
      "cwe": "CWE-20",
      "title": "Cisco Meraki Hardening Release - Input Validation Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76468"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-97714",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Absolute Security",
      "product": "Secure Access",
      "cwe": "CWE-400",
      "title": "Denial of service vulnerability in Secure Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97714"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-46570",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-122",
      "title": "In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_index_walk_down() in libntfs-3g/index.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by reading the special crafted file metadata.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46570"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-62251",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sipcapture",
      "product": "homer",
      "cwe": "CWE-89",
      "title": "Homer: Authenticated SQL Injection via Unvalidated rawquery Field in /api/v4/statistics/query",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62251"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-105816",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HashiCorp",
      "product": "Vault",
      "cwe": "CWE-22",
      "title": "Vault Vulnerable to Arbitrary Code Execution via Plugin Catalog Entries Restored From Raft Snapshots",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105816"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-102256",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SonicWall",
      "product": "SMA1000",
      "cwe": "CWE-78",
      "title": "Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 appliance which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102256"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-76266",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-269",
      "title": "Local Privilege Escalation through Linux Package Upgrades in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76266"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-103435",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Anthropic",
      "product": "@anthropic-ai/claude-code",
      "cwe": "CWE-22",
      "title": "Arbitrary File Write via Write-Time Symlink Following (TOCTOU) in Claude Code",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103435"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-106056",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rundeck",
      "product": "rundeck",
      "cwe": "CWE-78",
      "title": "Rundeck before 6.2.0 OS Command Injection via Windows Job Option Quoting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106056"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-106058",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gitahead",
      "product": "gitahead",
      "cwe": "CWE-78",
      "title": "GitAhead through 2.7.1 OS Command Injection via Git Filter Filenames",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106058"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-106510",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "backstage",
      "product": "backstage",
      "cwe": "CWE-183",
      "title": "Backstage: Remote code execution via crafted markdown_extensions in TechDocs mkdocs.yml",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106510"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-106556",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "backstage",
      "product": "backstage",
      "cwe": "CWE-78",
      "title": "Backstage: Configuration bypass in TechDocs mkdocs.yml sanitization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106556"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-106557",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "backstage",
      "product": "backstage",
      "cwe": "CWE-22",
      "title": "Backstage: Improper input validation in TechDocs Markdown extension configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106557"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-42708",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AF themes",
      "product": "WP Post Author",
      "cwe": "CWE-89",
      "title": "WordPress WP Post Author plugin <= 4.0.0 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42708"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-42710",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "10Web",
      "product": "Slider by 10Web",
      "cwe": "CWE-89",
      "title": "WordPress Slider by 10Web plugin <= 1.2.63 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42710"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-42713",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gopiplus",
      "product": "Post title marquee scroll",
      "cwe": "CWE-89",
      "title": "WordPress Post title marquee scroll plugin <= 9.9 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42713"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-42714",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Piggly Dev",
      "product": "Pix por Piggly (para Woocommerce)",
      "cwe": "CWE-89",
      "title": "WordPress Pix por Piggly (para Woocommerce) plugin <= 2.1.2 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42714"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-92543",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Docker",
      "product": "Docker Engine",
      "cwe": "CWE-295",
      "title": "Docker Engine insecure-registry fallback via malicious DNS responses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92543"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-107162",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ExpressGateway",
      "product": "express-gateway",
      "cwe": "CWE-287",
      "title": "Express Gateway through 1.16.11 OAuth 2.0 Refresh Token Validation Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107162"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-107281",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AsyncHttpClient",
      "product": "async-http-client",
      "cwe": "CWE-346",
      "title": "AsyncHttpClient: Connection pool key omits the authenticated principal, so an NTLM or Negotiate connection is reused across identities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107281"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-76467",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Campus Gateway Software",
      "cwe": "CWE-664",
      "title": "Cisco Meraki Software Hardening Release - Resource Lifetime Management Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76467"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-92531",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BugTracker.NET",
      "product": "BugTracker.NET",
      "cwe": "CWE-78",
      "title": "Improper Neutralization of Special Elements used in an OS Command in BugTracker.NET",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92531"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-92532",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BugTracker.NET",
      "product": "BugTracker.NET",
      "cwe": "CWE-434",
      "title": "Unrestricted Upload of File with Dangerous Type in BugTracker.NET",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92532"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-96335",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPMU DEV",
      "product": "Forminator",
      "cwe": "CWE-862",
      "title": "WordPress Forminator plugin <= 1.57.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96335"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-107161",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-122",
      "title": "Cyrus-sasl: heap buffer overflow in cyrus-sasl add_to_challenge() allows malicious server to crash or compromise digest-md5 clients",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107161"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-107212",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "qax-os",
      "product": "excelize",
      "cwe": "CWE-770",
      "title": "Excelize: Unbounded row number in Rows.Columns makes GetRows and the Rows iterator loop for days",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107212"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-107214",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "qax-os",
      "product": "excelize",
      "cwe": "CWE-248",
      "title": "Excelize Decrypt: unrecoverable panics on malformed OLE/CFB encrypted workbooks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107214"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-107215",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "qax-os",
      "product": "excelize",
      "cwe": "CWE-789",
      "title": "Excelize: extractPart allocates attacker-controlled, unbounded and negative-sized buffers from CFB directory entries: remote panic / OOM DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107215"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-107216",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "qax-os",
      "product": "excelize",
      "cwe": "CWE-674",
      "title": "Excelize ANCHORARRAY: mutually-referencing array formulas recurse unboundedly via re-entrant CalcCellValue, causing a fatal stack overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107216"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-107217",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "qax-os",
      "product": "excelize",
      "cwe": "CWE-129",
      "title": "Excelize ColumnNameToNumber: int64 overflow yields an out-of-domain coordinate with nil error, causing negative slice index panic on r=\"0\" rows",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107217"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-107219",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "qax-os",
      "product": "excelize",
      "cwe": "CWE-400",
      "title": "Excelize: Unbounded spinCount in agile decryption burns CPU during OpenFile",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107219"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-107227",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AsyncHttpClient",
      "product": "async-http-client",
      "cwe": "CWE-400",
      "title": "AsyncHttpClient: Unbounded WebSocket permessage-deflate decompression enables a decompression-bomb denial of service when compression is enabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107227"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-107232",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AsyncHttpClient",
      "product": "async-http-client",
      "cwe": "CWE-319",
      "title": "AsyncHttpClient: Origin credentials sent in cleartext to a proxy that rejects the CONNECT",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107232"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-46572",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-122",
      "title": "In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_ib_cut_tail() in libntfs-3g/index.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by creating a file in a specially crafted directory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46572"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-76469",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Campus Gateway Software",
      "cwe": "CWE-691",
      "title": "Cisco Meraki Security Hardening Release: October 2026 Insufficient Control Flow Management Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76469"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-107177",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ExpressGateway",
      "product": "express-gateway",
      "cwe": "CWE-1394",
      "title": "Express Gateway through 1.16.11 Hardcoded Default cipherKey Exposes OAuth Tokens",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107177"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-107230",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AsyncHttpClient",
      "product": "async-http-client",
      "cwe": "CWE-346",
      "title": "AsyncHttpClient: Pooled connections can still be shared across NTLM, Negotiate and proxy logins",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107230"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-106164",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software",
      "product": "Telerik Document Processing Libraries",
      "cwe": "CWE-835",
      "title": "Infinite Loop in Telerik Document Processing XLS Import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106164"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-20362",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Finesse",
      "cwe": "CWE-918",
      "title": "Cisco Finesse Server-Side Request Forgery Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20362"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-89322",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HashiCorp",
      "product": "Vault",
      "cwe": "CWE-178",
      "title": "Vault ACL Policy Evaluation May Allow Bypass of Deny Restrictions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89322"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-102257",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SonicWall",
      "product": "SMA1000",
      "cwe": "CWE-22",
      "title": "A Zip Slip vulnerability in the in the SMA1000 Appliance Management Console (AMC) interface allows an attacker to extract files outside the intended destination directory using a specially crafted archive, resulting in remote code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102257"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-42617",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-122",
      "title": "In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_ir_to_ib() in index.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by extending a directory, e.g., by creating a file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42617"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-42618",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-122",
      "title": "In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_decompress() in compress.c that allows an attacker to corrupt one byte of heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by reading the special crafted file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42618"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-43976",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wger-project",
      "product": "wger",
      "cwe": "CWE-863",
      "title": "wger: cross-tenant admin notes/contracts leak via gym=None bypass (5 views)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43976"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-46434",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wger-project",
      "product": "wger",
      "cwe": "CWE-269",
      "title": "wger: Trainer Privilege Escalation - Improper Privilege Management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46434"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-92533",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BugTracker.NET",
      "product": "BugTracker.NET",
      "cwe": "CWE-24",
      "title": "Path Traversal in BugTracker.NET",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92533"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-94662",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unlimited Elements",
      "product": "Unlimited Elements For Elementor (Free Widgets, Addons, Templates)",
      "cwe": "CWE-79",
      "title": "WordPress Unlimited Elements For Elementor plugin <= 2.0.19 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94662"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-94670",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Everest Forms",
      "product": "Everest Forms",
      "cwe": "CWE-79",
      "title": "WordPress Everest Forms plugin <= 3.6.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94670"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-95595",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fontsplugin",
      "product": "Disable and Remove Google Fonts | GDPR & DSGVO friendly",
      "cwe": "CWE-79",
      "title": "WordPress Disable and Remove Google Fonts | GDPR & DSGVO friendly plugin <= 2.0.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95595"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-97715",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Absolute Security",
      "product": "Secure Access",
      "cwe": "CWE-400",
      "title": "Denial of Service in Absolute Secure Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97715"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-105138",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "obot-platform",
      "product": "obot",
      "cwe": "CWE-522",
      "title": "Obot 0.12.0 before 0.26.2 Credential Exposure via MCP Catalog Entry API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105138"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-106560",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "backstage",
      "product": "backstage",
      "cwe": "CWE-22",
      "title": "Backstage: Improper repository path validation in a Scaffolder backend module",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106560"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-107159",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "miniupnp project",
      "product": "miniupnpd",
      "cwe": "CWE-369",
      "title": "MiniUPnPd through 2.3.11 Divide-by-Zero DoS via SSDP M-SEARCH MX Header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107159"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-107180",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-287",
      "title": "MISP: Forced TOTP Enrolment Bypassed via Non-Browser Request Types on otp_required Instances",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107180"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-107223",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "qax-os",
      "product": "excelize",
      "cwe": "CWE-789",
      "title": "Excelize: Unbounded <col max> attribute is loaded with no MaxColumns check and expanded per-column by flatCols(), so any column mutator hangs or OOMs the process",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107223"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-107270",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gophish",
      "product": "gophish",
      "cwe": "CWE-639",
      "title": "Gophish through 0.12.1 Object Takeover via Client-Supplied ID on API Create Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107270"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-92415",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Jackrabbit",
      "cwe": "CWE-470",
      "title": "Apache Jackrabbit: DavEx client runs Class.forName + (String)-constructor on server-controlled error bodies",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92415"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-92542",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Docker",
      "product": "Docker Engine",
      "cwe": "CWE-290",
      "title": "Blind VXLAN injection into encrypted overlay networks from cluster peer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92542"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-104074",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coturn",
      "product": "coturn",
      "cwe": "CWE-908",
      "title": "Coturn 4.10.0 Uninitialized Stack Memory Disclosure via ERROR-CODE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104074"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-107207",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LMCache",
      "product": "LMCache",
      "cwe": "CWE-306",
      "title": "LMCache through 0.5.5 Missing Authentication in Frontend Node Catalog Allows SSRF Allowlist Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107207"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-107271",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gophish",
      "product": "gophish",
      "cwe": "CWE-348",
      "title": "Gophish through 0.12.1 Login Rate Limit Bypass via X-Forwarded-For Spoofing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107271"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-107280",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AsyncHttpClient",
      "product": "async-http-client",
      "cwe": "CWE-1275",
      "title": "AsyncHttpClient: Cookie Domain attribute is not checked against the public suffix list, so a cookie can be set for co.uk",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107280"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-107353",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ljharb",
      "product": "traverse",
      "cwe": "CWE-1321",
      "title": "traverse: set() can write to built-in prototypes via an untrusted path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107353"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-107176",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift Container Platform 4",
      "cwe": "CWE-250",
      "title": "Cluster-samples-operator: role reads all secrets in openshift-config, not just pull-secret",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107176"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-107228",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AsyncHttpClient",
      "product": "async-http-client",
      "cwe": "CWE-287",
      "title": "AsyncHttpClient CookieStore Silently Overrides Caller's Explicit Cookie Header via setHeader (Bypass of CVE-2024-53990 Fix)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107228"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-1403",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-770",
      "title": "Allocation of Resources Without Limits or Throttling in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1403"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-20321",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Application Policy Infrastructure Controller (APIC)",
      "cwe": "CWE-544",
      "title": "Cisco Application Policy Infrastructure Controller API Command Injection Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20321"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-41958",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "visidata",
      "product": "visidata",
      "cwe": "CWE-22",
      "title": "A path traversal vulnerability exists in the unzip_http RemoteZipFile extract functionality of VisiData (version(s): dev (commit 38b21f78)). A specially crafted .zip file can lead to arbitrary file write. An attacker can provide a crafted URL to trigger this vulnerability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41958"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-46438",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wger-project",
      "product": "wger",
      "cwe": "CWE-639",
      "title": "wger: Cross-User Data Corruption via Missing Ownership Check on WorkoutLog.slot_entry",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46438"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-62179",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "praisonai-platform",
      "cwe": "CWE-862",
      "title": "PraisonAI: Platform members can delete owner issue dependencies through member-owned related issues",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62179"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-76265",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-284",
      "title": "Improper Access Control through REST API Endpoints in Splunk Secure Gateway",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76265"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-76269",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-639",
      "title": "Improper Access Control in Search Job Retrieval through the REST API in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76269"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-76270",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-89",
      "title": "Structured Query Language (SQL) Injection in the SPL2 Module Catalog in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76270"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-76271",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-407",
      "title": "Denial of Service (DoS) in the Discover Splunk Observability Cloud app for Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76271"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-76274",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-918",
      "title": "Server-Side Request Forgery (SSRF) through the REST API in Splunk App for Splunk Observability Cloud",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76274"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-76488",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Application Policy Infrastructure Controller (APIC)",
      "cwe": "CWE-264",
      "title": "Cisco Application Policy Infrastructure Controller Authenticated Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76488"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-107220",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "qax-os",
      "product": "excelize",
      "cwe": "CWE-125",
      "title": "Excelize: Panic in cellInRange on a worksheet with an empty mergeCell ref",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107220"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-107221",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "qax-os",
      "product": "excelize",
      "cwe": "CWE-787",
      "title": "Excelize: a row whose earlier cell has a higher column reference than its last cell panics index out of range on almost every worksheet read API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107221"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-107222",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "qax-os",
      "product": "excelize",
      "cwe": "CWE-129",
      "title": "Excelize: GetConditionalFormats indexes conditional-formatting rule sub-elements with no length or nil check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107222"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-107224",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "qax-os",
      "product": "excelize",
      "cwe": "CWE-190",
      "title": "Excelize: A Zip64 uncompressed-size of 2^63 panics OpenFile/OpenReader",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107224"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-107225",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "qax-os",
      "product": "excelize",
      "cwe": "CWE-20",
      "title": "Excelize: GetStyle panics on a negative fillId, borderId or fontId in styles.xml",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107225"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-107174",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "OpenShift Serverless",
      "cwe": "CWE-61",
      "title": "Source-to-image: source-to-image: security boundary bypass via absolute symbolic link extraction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107174"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-33586",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OVHcloud",
      "product": "OVHcloud",
      "cwe": "CWE-290",
      "title": "Authenticated SMTP Sender Address Forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33586"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-76280",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-732",
      "title": "Incorrect Permission Assignment for App Key Value Store Collections in Splunk Secure Gateway",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76280"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-106064",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-119",
      "title": "Gimp: gimp: heap buffer overflow in gif export on oversized image dimensions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106064"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-106065",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-119",
      "title": "Gimp: gimp: heap buffer overflow in pcx export on oversized image dimensions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106065"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-106066",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-119",
      "title": "Gimp: gimp: heap buffer overflow in raw data export on oversized image dimensions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106066"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-106067",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-119",
      "title": "Gimp: gimp: heap buffer overflow in hot color filter on oversized image",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106067"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-106559",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "backstage",
      "product": "backstage",
      "cwe": "CWE-22",
      "title": "Backstage: Improper input validation in Confluence to Markdown scaffolder module",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106559"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-107269",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gophish",
      "product": "gophish",
      "cwe": "CWE-208",
      "title": "Gophish through 0.12.1 Username Enumeration via POST /login Timing Discrepancy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107269"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-107276",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-362",
      "title": "MISP Email OTP Race Condition Allows One-Time Password to Be Consumed by Multiple Concurrent Requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107276"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-107352",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "Amazon Athena",
      "cwe": "CWE-424",
      "title": "Missing authorization checks in Amazon Athena engine version 3 request handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107352"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-106579",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-551",
      "title": "ImageMagick: Policy Bypass when using coder as the domain.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106579"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-107167",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-416",
      "title": "M17n-lib: heap use-after-free write in re_init_ic()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107167"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-107168",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-835",
      "title": "M17n-lib: parser infinite loop on malformed utf-8 in count_utf_8_chars()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107168"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-107169",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-476",
      "title": "M17n-lib: null-pointer write in read_mtext_element() on malformed utf-8",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107169"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2025-70519",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "The device log component of Fanvil x7a firmware version 2.6.0.1182 does not properly sanitize or encode reflected user supplied data. The lack of sanitization allows for the injection of HTML which can be used to execute malicious JavaScript code on any target browser which renders the device log component.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-70519"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-94154",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "r3098",
      "product": "Aurora Heatmap",
      "cwe": "CWE-79",
      "title": "Aurora Heatmap <= 1.7.2 - Unauthenticated Stored Cross-Site Scripting via 'url' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94154"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-102258",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SonicWall",
      "product": "SMA1000",
      "cwe": "CWE-79",
      "title": "Post-authentication Stored Cross-Site Scripting (XSS) vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to store and potentially execute arbitrary JavaScript code in the Appliance Management Console (AMC).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-102258"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-107363",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenStack",
      "product": "Zaqar",
      "cwe": "CWE-472",
      "title": "In OpenStack Zaqar before 23.0.1, the WebSocket transport fails to bind the project identifier in subsequent requests to the project authenticated by the Keystone token. An authenticated user with a valid token for one project may substitute another project's UUID to enumerate, inspect, create, or delete queues belonging to that project, resulting in unauthorized disclosure, modification, or loss of queue data. Only deployments using the WebSocket transport with Keystone authentication are affected.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107363"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-97717",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Absolute Security",
      "product": "Secure Access",
      "cwe": "CWE-400",
      "title": "Denial of Service in Absolute Secure Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97717"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-105818",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HashiCorp",
      "product": "Vault",
      "cwe": "CWE-345",
      "title": "Vault PKI ACME Issues Certificate With Unvalidated SANs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105818"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-106565",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-400",
      "title": "ImageMagick: Infinite Loop in bzip2 compressed images.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106565"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-106567",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-196",
      "title": "ImageMagick: Infinite Loop in PSD decoder on 32-bit builds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106567"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-106578",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-590",
      "title": "ImageMagick: Invalid Memory Free in MVG decoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106578"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-107151",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Satellite 6",
      "cwe": "CWE-306",
      "title": "Rubygem-smart_proxy_dynflow: task update and done callbacks accept unauthenticated requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107151"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-107209",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-415",
      "title": "ImageMagick: Use-After-Free in RSVG decoder that is build without cairo support",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107209"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-107285",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AsyncHttpClient",
      "product": "async-http-client",
      "cwe": "CWE-319",
      "title": "AsyncHttpClient: WebSocket proxy credentials sent to the origin server over a CONNECT tunnel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107285"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-107314",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pgjdbc",
      "product": "pgjdbc",
      "cwe": "CWE-636",
      "title": "pgjdbc does not enforce requireAuth when the value excludes every authentication method",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107314"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-20038",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco NX-OS System Software in ACI Mode",
      "cwe": "CWE-284",
      "title": "Cisco Nexus 9000 Series Fabric Switches in ACI Mode Policy-Based Redirect Endpoint Group Contract Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20038"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-20173",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco NX-OS Software",
      "cwe": "CWE-770",
      "title": "Cisco NX-OS Software Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20173"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-42532",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "visidata",
      "product": "visidata",
      "cwe": "CWE-22",
      "title": "A path traversal vulnerability exists in the EmailSheet extract_parts functionality of VisiData (version(s): dev (commit 38b21f78)). A specially crafted .eml file can lead to arbitrary file write. An attacker can provide a malicious file to trigger this vulnerability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42532"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-46571",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-125",
      "title": "In NTFS-3G before 2026.7.7, a out-of-bounds read exists in ntfs_fix_file_name() in libntfs-3g/reparse.c that allows an attacker to read possibly confidential information in ntfs-3g process memory by crafting a malicious NTFS image. The out-of-bounds read is triggered by a readlink on a corrupted file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46571"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-88514",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-200",
      "title": "An issue in iTerm2 macOS before 3.6.12 allows a local attacker to obtain sensitive information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88514"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-107166",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Open5GS",
      "cwe": "CWE-400",
      "title": "Open5GS GTP-U Receive Path gtp-path.c ogs_pfcp_xact_local_create allocation of resources",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107166"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-17538",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "latepoint",
      "product": "Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress",
      "cwe": "CWE-639",
      "title": "Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress <= 5.6.9 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Customer PII Modification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17538"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-45161",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wger-project",
      "product": "wger",
      "cwe": "CWE-352",
      "title": "wger: trainer_login accepts GET - CSRF bypass enables forced session rebinding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45161"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-105820",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HashiCorp",
      "product": "Vault Enterprise",
      "cwe": "CWE-22",
      "title": "Vault ACL Policy Cache Vulnerable to Cross-Namespace Policy Resolution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105820"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-76286",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk MCP Server",
      "cwe": "CWE-918",
      "title": "Server-Side Request Forgery (SSRF) through Custom API Tools in Splunk MCP Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76286"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-105139",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "obot-platform",
      "product": "obot",
      "cwe": "CWE-863",
      "title": "Obot 0.26.0 before 0.26.2 Authorization Bypass via vMCP Profile Prompts and Resources",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105139"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-106563",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "backstage",
      "product": "backstage",
      "cwe": "CWE-20",
      "title": "Backstage: Improper entity validation in deprecated Kubernetes services endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106563"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-106564",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-122",
      "title": "ImageMagick: Heap Buffer Over-Write in EXR decoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106564"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-106568",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-835",
      "title": "ImageMagick: Infinite Loop when reading a crafted XMP profile",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106568"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-106569",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-770",
      "title": "ImageMagick: Denial of service in ASE decoder because of missing security checks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106569"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-106572",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-674",
      "title": "ImageMagick: Stack Overflown CALS decoder due to missing depth check.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106572"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-106573",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-400",
      "title": "ImageMagick: Denial of service in MVG decoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106573"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-106574",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-122",
      "title": "ImageMagick: Heap Buffer Over-Write in distributed pixel cache server will result in a crash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106574"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-106575",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-775",
      "title": "ImageMagick: Unclosed file pointer in magick script",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106575"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-106576",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-400",
      "title": "ImageMagick: Denial of service possible when parsing an XMP profile.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106576"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-106577",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-94",
      "title": "ImageMagick: Code Injection in the postscript coders",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106577"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-107175",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-284",
      "title": "MISP Correlation Engine Fails to Refresh When Event Distribution or Sharing Group Changes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107175"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-107208",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-400",
      "title": "ImageMagick: Denial of service with crafted XMP profile",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107208"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-107210",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-409",
      "title": "ImageMagick: Policy Bypass in MAT decoder when reading highly compressed data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107210"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-107218",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "qax-os",
      "product": "excelize",
      "cwe": "CWE-129",
      "title": "Excelize: RIGHT() on supplementary-plane text slices with a negative index and panics",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107218"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-107273",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gophish",
      "product": "gophish",
      "cwe": "CWE-918",
      "title": "Gophish 0.11.0 through 0.12.1 SSRF via POST /api/import/site",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107273"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-107278",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-20",
      "title": "MISP Object Sync Drops Objects and Attributes When Description Is Empty",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107278"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-107315",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pgjdbc",
      "product": "pgjdbc",
      "cwe": "CWE-226",
      "title": "pgjdbc pads a value shorter than its declared length with bytes of earlier statements (rather than zeros)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107315"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-101886",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Jabber for Android",
      "cwe": "CWE-22",
      "title": "Cisco Jabber for Android Path Traversal via Shared Content URI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101886"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-106571",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-190",
      "title": "ImageMagick: Heap Buffer Over-Write in GetVirtualPixels api will result in a crash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106571"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-106561",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "backstage",
      "product": "backstage",
      "cwe": "CWE-200",
      "title": "Backstage: Sensitive information disclosure in Kubernetes resource queries",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106561"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-76437",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco License On-Prem",
      "cwe": "CWE-78",
      "title": "Cisco Smart Software Manager On-Prem Command Injection Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76437"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-76452",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco License On-Prem",
      "cwe": "CWE-89",
      "title": "Cisco Smart Software Manager On-Prem SQL Injection Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76452"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-46437",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wger-project",
      "product": "wger",
      "cwe": "CWE-287",
      "title": "wger: API credentials remain valid after logout/password change",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46437"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-20032",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco NX-OS Software",
      "cwe": "CWE-653",
      "title": "Cisco NX-OS Software Python Sandbox Escape Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20032"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-76264",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-863",
      "title": "Improper Authorization through the REST API in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76264"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-76267",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-117",
      "title": "Log Injection through the REST API in Splunk App for Splunk O11y Cloud",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76267"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-76272",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-862",
      "title": "Missing Access Control through the REST API in Splunk Secure Gateway",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76272"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-76273",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-20",
      "title": "Improper Input Validation through the collect Command in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76273"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-76275",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-285",
      "title": "Improper Authorization in Search Job Listings through the REST API in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76275"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-76276",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-1188",
      "title": "Information Disclosure in the Discover Splunk Observability Cloud app through Splunk Web for Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76276"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-76278",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-639",
      "title": "Authorization Bypass in SPL2 Module Permissions in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76278"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-76279",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-20",
      "title": "Improper Input Validation of Index Names through the collect Command in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76279"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-106562",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "backstage",
      "product": "backstage",
      "cwe": "CWE-754",
      "title": "Backstage: Incorrect authorization in search engine permission filtering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106562"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-106570",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-400",
      "title": "ImageMagick: Denial of service in distributed pixel cache server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106570"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-107313",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pgjdbc",
      "product": "pgjdbc",
      "cwe": "CWE-201",
      "title": "pgjdbc stores bytes of earlier messages in place of a large value on GSS-encrypted connections",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107313"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-76277",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-20",
      "title": "Improper Input Validation of Native Splunk Usernames through the REST API in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76277"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-106566",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-61",
      "title": "ImageMagick: Policy Bypass in delegate symlink cleanup due to missing check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106566"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-106580",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-284",
      "title": "ImageMagick: Policy Bypass in CUT encoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-106580"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-107229",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AsyncHttpClient",
      "product": "async-http-client",
      "cwe": "CWE-384",
      "title": "AsyncHttpClient: Incomplete origin checks in the default cookie store allow cookie tossing onto public-suffix and IP-address hosts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107229"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-107283",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AsyncHttpClient",
      "product": "async-http-client",
      "cwe": "CWE-338",
      "title": "AsyncHttpClient: Digest authentication cnonce generated with a non-cryptographic random source",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107283"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-107284",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AsyncHttpClient",
      "product": "async-http-client",
      "cwe": "CWE-345",
      "title": "AsyncHttpClient: WebSocket handshake continues after a failed Sec-WebSocket-Accept check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107284"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-107170",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-476",
      "title": "M17n-lib: null dereference in minput_open_im() after failed m17n_init()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107170"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-105140",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "obot-platform",
      "product": "obot",
      "cwe": "CWE-362",
      "title": "Obot 0.25.0 before 0.25.6 and 0.26.0 before 0.26.1 Race Condition Restores Revoked Group Membership",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105140"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-107272",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gophish",
      "product": "gophish",
      "cwe": "CWE-79",
      "title": "Gophish through 0.12.1 XSS via Unescaped SMTP Server Error Messages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107272"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-107125",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "XnView",
      "product": "Classic",
      "cwe": "CWE-119",
      "title": "XnView Classic FLI File heap-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-107125"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2025-70515",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "The device log component of Fanvil x7a firmware version 2.6.0.1182 does not properly sanitize or encode reflected user supplied data. The lack of sanitization allows for the injection of HTML which can be used to execute malicious JavaScript code on any target browser which renders the device log component.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-70515"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2025-70517",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "The request handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce any cross-origin resource protection for any state-changing request performed against the applications. Due to the lack of protection, cross-origin boundary can be completely bypassed, allowing for Cross-Site Request Forgery Attacks against any endpoint.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-70517"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2025-70520",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "The websocket handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce proper authentication restrictions against sessionless users. The lack of restrictions grants anyone the ability to view any device resources such as operational logs or perform diagnostic requests.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-70520"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2025-70522",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "The request handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce any cross-origin resource protection for any state-changing request performed against the applications. Due to the lack of protection, cross-origin boundary can be completely bypassed, allowing for Cross-Site Request Forgery Attacks against any endpoint.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-70522"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-42616",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "In NTFS-3G before 2026.7.7, a heap buffer overflow exists in cat() in ntfscat.c that allows an attacker to corrupt heap memory in the ntfscat binary by crafting a malicious NTFS image. The overflow is triggered by reading a file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42616"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-46569",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_ib_copy_tail(), in libntfs-3g/index.c, that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by extending a directory, e.g., by creating a file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46569"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-56851",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "golang.org/x/text",
      "product": "golang.org/x/text/secure/precis",
      "cwe": null,
      "title": "Panic parsing crafted input in x/text/secure/precis in golang.org/x/text",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56851"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-76281",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-284",
      "title": "Improper Access Control in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76281"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-76282",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-664",
      "title": "Improper Control of a Resource Through its Lifetime in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76282"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-76283",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-693",
      "title": "Protection Mechanism Failure in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76283"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-76284",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-707",
      "title": "Improper Neutralization in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76284"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-76285",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-710",
      "title": "Improper Adherence to Coding Standards in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76285"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-98373",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm/hugetlb: preserve mremap address delta when skipping page tables",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98373"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-98374",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tcp: fix use-after-free of retransmit_skb_hint in tcp_send_synack()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-98374"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-103371",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Geode",
      "cwe": null,
      "title": "Apache Geode: Management REST API: Insertion of Sensitive Information into Log File",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103371"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2014-0050",
      "detail": "EXPLOIT PUBLISHED — CVE-2014-0050. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2015-6420",
      "detail": "EXPLOIT PUBLISHED — CVE-2015-6420. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2016-1000027",
      "detail": "EXPLOIT PUBLISHED — CVE-2016-1000027. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2017-16138",
      "detail": "EXPLOIT PUBLISHED — CVE-2017-16138 (HackerOne mime node module). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2018-20852",
      "detail": "EXPLOIT PUBLISHED — CVE-2018-20852. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2019-16935",
      "detail": "EXPLOIT PUBLISHED — CVE-2019-16935. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2019-5010",
      "detail": "EXPLOIT PUBLISHED — CVE-2019-5010 (Python). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2019-9740",
      "detail": "EXPLOIT PUBLISHED — CVE-2019-9740. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2019-9947",
      "detail": "EXPLOIT PUBLISHED — CVE-2019-9947. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2019-9948",
      "detail": "EXPLOIT PUBLISHED — CVE-2019-9948. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2020-15250",
      "detail": "EXPLOIT PUBLISHED — CVE-2020-15250 (junit-team junit4). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2020-26217",
      "detail": "EXPLOIT PUBLISHED — CVE-2020-26217 (x-stream xstream). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2020-26258",
      "detail": "EXPLOIT PUBLISHED — CVE-2020-26258 (x-stream xstream). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2020-26259",
      "detail": "EXPLOIT PUBLISHED — CVE-2020-26259 (x-stream xstream). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2020-8492",
      "detail": "EXPLOIT PUBLISHED — CVE-2020-8492. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2020-9054",
      "detail": "EXPLOIT PUBLISHED — CVE-2020-9054 (ZyXEL NAS326). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-21341",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-21341 (x-stream xstream). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-21342",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-21342 (x-stream xstream). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-21343",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-21343 (x-stream xstream). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-21344",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-21344 (x-stream xstream). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-21345",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-21345 (x-stream xstream). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-21346",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-21346 (x-stream xstream). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-21347",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-21347 (x-stream xstream). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-21349",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-21349 (x-stream xstream). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-21350",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-21350 (x-stream xstream). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-21351",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-21351 (x-stream xstream). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-29425",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-29425 (Apache Software Foundation Apache Commons IO). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-39140",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-39140 (x-stream xstream). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-39141",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-39141 (x-stream xstream). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-39147",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-39147 (x-stream xstream). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-39148",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-39148 (x-stream xstream). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-39149",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-39149 (x-stream xstream). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-39150",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-39150 (x-stream xstream). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-39151",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-39151 (x-stream xstream). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-39152",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-39152 (x-stream xstream). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-39153",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-39153 (x-stream xstream). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-39154",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-39154 (x-stream xstream). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2022-0235",
      "detail": "EXPLOIT PUBLISHED — CVE-2022-0235 (node-fetch/node-fetch). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2022-2596",
      "detail": "EXPLOIT PUBLISHED — CVE-2022-2596 (node-fetch/node-fetch). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2022-42003",
      "detail": "EXPLOIT PUBLISHED — CVE-2022-42003. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2022-42004",
      "detail": "EXPLOIT PUBLISHED — CVE-2022-42004. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2023-22894",
      "detail": "EXPLOIT PUBLISHED — CVE-2023-22894. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2023-50572",
      "detail": "EXPLOIT PUBLISHED — CVE-2023-50572. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2024-1102",
      "detail": "EXPLOIT PUBLISHED — CVE-2024-1102 (jberet). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-14611",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-14611 (Gladinet CentreStack and TrioFox). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-25249",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-25249 (Fortinet FortiSwitchManager). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-5914",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-5914 (libarchive). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-101917",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-101917 (jpadilla pyjwt). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-101918",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-101918 (jpadilla pyjwt). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-102265",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-102265 (jpadilla pyjwt). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-102266",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-102266 (jpadilla pyjwt). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-102268",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-102268 (jpadilla pyjwt). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-104973",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-104973 (makeplane plane). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10520",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10520 (ivanti Sentry). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-105226",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-105226 (osCommerce2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-105232",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-105232 (kishor-23 food-waste-management-system). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-105245",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-105245 (sgl-project sglang). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-105254",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-105254 (itsourcecode Online Admission System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-105286",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-105286 (Totolink A3002MU). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-105290",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-105290 (feelec-yishu feelcrm-os). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-105329",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-105329 (TallCMS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-105385",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-105385 (onetwothreeneth HospitalManagementSystem). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-105389",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-105389 (feelec-yishu feelcrm-os). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-105468",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-105468 (girishsaraf Online-Appointment-Booking-System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-105472",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-105472 (girishsaraf Online-Appointment-Booking-System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-105571",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-105571 (PickMall Lilishop). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-105611",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-105611 (chillzhuang SpringBlade). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-105705",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-105705 (SourceCodester Drug Recommendation System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-105742",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-105742 (docling-project docling). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-105744",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-105744 (docling-project docling). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-105748",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-105748 (docling-project docling). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-106214",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-106214 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-21589",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-21589 (Atlassian Bamboo Data Center). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48558",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48558 (SimpleHelp). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55255",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55255 (langflow-ai langflow). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55653",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55653 (Red Hat Enterprise Linux 10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-56290",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-56290 (JoomlaCK.fr Page Builder CK extension for Joomla). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-69147",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-69147 (vllm-project vllm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-77226",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-77226 (Camunda 7). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-81914",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-81914 (Apache Software Foundation Apache Airflow Google provider). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86843",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86843 (Apache Software Foundation Apache Airflow Teradata provider). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90462",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90462 (Red Hat Enterprise Linux 10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90996",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90996 (Red Hat Enterprise Linux 10). Public exploit reference added."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2018-14647",
      "detail": "RESCORED — CVE-2018-14647 (The Python Project Python). CVSS 5.3 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2019-16056",
      "detail": "RESCORED — CVE-2019-16056. CVSS 5.3 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2019-18348",
      "detail": "RESCORED — CVE-2019-18348. CVSS 5.4 → 6.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2019-20907",
      "detail": "RESCORED — CVE-2019-20907. CVSS 5.5 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2019-5010",
      "detail": "RESCORED — CVE-2019-5010 (Python). CVSS 5.9 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2019-9636",
      "detail": "RESCORED — CVE-2019-9636. CVSS 5.3 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2019-9740",
      "detail": "RESCORED — CVE-2019-9740. CVSS 6.5 → 6.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2019-9947",
      "detail": "RESCORED — CVE-2019-9947. CVSS 5.4 → 6.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2020-10735",
      "detail": "RESCORED — CVE-2020-10735 (python). CVSS 6.2 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2020-15250",
      "detail": "RESCORED — CVE-2020-15250 (junit-team junit4). CVSS 4.4 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2020-26217",
      "detail": "RESCORED — CVE-2020-26217 (x-stream xstream). CVSS 8 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2020-26258",
      "detail": "RESCORED — CVE-2020-26258 (x-stream xstream). CVSS 6.3 → 7.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2021-21342",
      "detail": "RESCORED — CVE-2021-21342 (x-stream xstream). CVSS 5.3 → 9.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2021-21343",
      "detail": "RESCORED — CVE-2021-21343 (x-stream xstream). CVSS 5.3 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2021-21344",
      "detail": "RESCORED — CVE-2021-21344 (x-stream xstream). CVSS 5.3 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2021-21345",
      "detail": "RESCORED — CVE-2021-21345 (x-stream xstream). CVSS 5.8 → 9.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2021-21346",
      "detail": "RESCORED — CVE-2021-21346 (x-stream xstream). CVSS 6.1 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2021-21347",
      "detail": "RESCORED — CVE-2021-21347 (x-stream xstream). CVSS 6.1 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2021-21348",
      "detail": "RESCORED — CVE-2021-21348 (x-stream xstream). CVSS 5.3 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2021-21349",
      "detail": "RESCORED — CVE-2021-21349 (x-stream xstream). CVSS 6.1 → 8.6 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2021-21350",
      "detail": "RESCORED — CVE-2021-21350 (x-stream xstream). CVSS 5.3 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2021-21351",
      "detail": "RESCORED — CVE-2021-21351 (x-stream xstream). CVSS 5.4 → 9.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2021-29425",
      "detail": "RESCORED — CVE-2021-29425 (Apache Software Foundation Apache Commons IO). CVSS 6.5 → 4.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2021-29505",
      "detail": "RESCORED — CVE-2021-29505 (x-stream xstream). CVSS 7.5 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2021-36342",
      "detail": "RESCORED — CVE-2021-36342 (Dell CPG BIOS). CVSS 7.5 → 6.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2021-36343",
      "detail": "RESCORED — CVE-2021-36343 (Dell CPG BIOS). CVSS 7.5 → 6.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2021-39139",
      "detail": "RESCORED — CVE-2021-39139 (x-stream xstream). CVSS 8.5 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2021-39140",
      "detail": "RESCORED — CVE-2021-39140 (x-stream xstream). CVSS 6.5 → 6.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2021-39297",
      "detail": "RESCORED — CVE-2021-39297 (BUSINESS NOTEBOOK PCS BIOS; BUSINESS DESKTOP PCS BIOS; RETAIL POINT-OF-SALE SYSTEMS BIOS; WORKSTATIONS BIOS). CVSS 7.8 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2021-39298",
      "detail": "RESCORED — CVE-2021-39298 (AMD 2nd Gen EPYC). CVSS 6.5 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2021-39299",
      "detail": "RESCORED — CVE-2021-39299 (BUSINESS NOTEBOOK PCS BIOS; BUSINESS DESKTOP PCS BIOS; RETAIL POINT-OF-SALE SYSTEMS BIOS; WORKSTATIONS BIOS). CVSS 7.8 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2021-39300",
      "detail": "RESCORED — CVE-2021-39300 (BUSINESS NOTEBOOK PCS BIOS; BUSINESS DESKTOP PCS BIOS; RETAIL POINT-OF-SALE SYSTEMS BIOS; WORKSTATIONS BIOS). CVSS 7.3 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2021-39301",
      "detail": "RESCORED — CVE-2021-39301 (BUSINESS NOTEBOOK PCS BIOS; BUSINESS DESKTOP PCS BIOS; RETAIL POINT-OF-SALE SYSTEMS BIOS; WORKSTATIONS BIOS). CVSS 7.8 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2022-0235",
      "detail": "RESCORED — CVE-2022-0235 (node-fetch/node-fetch). CVSS 8.8 → 6.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2023-22894",
      "detail": "RESCORED — CVE-2023-22894. CVSS 9.8 → 4.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2023-43086",
      "detail": "RESCORED — CVE-2023-43086 (Dell Command Configure (DCC)). CVSS 7.3 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21043",
      "detail": "RESCORED — CVE-2025-21043 (Samsung Mobile Devices). CVSS 8.8 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-32151",
      "detail": "RESCORED — CVE-2025-32151 (Themekraft BuddyForms). CVSS 7.5 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-5154",
      "detail": "RESCORED — CVE-2025-5154 (PhonePe App). CVSS 4.6 → 1.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-9000",
      "detail": "RESCORED — CVE-2025-9000 (Mechrevo Control Center GX V2). CVSS 7.3 → 6.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-9016",
      "detail": "RESCORED — CVE-2025-9016 (Mechrevo Control Center GX V2). CVSS 7.3 → 6.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-101917",
      "detail": "RESCORED — CVE-2026-101917 (jpadilla pyjwt). CVSS 5.3 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-101918",
      "detail": "RESCORED — CVE-2026-101918 (jpadilla pyjwt). CVSS 5.3 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-102266",
      "detail": "RESCORED — CVE-2026-102266 (jpadilla pyjwt). CVSS 7.4 → 9.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-102267",
      "detail": "RESCORED — CVE-2026-102267 (jpadilla pyjwt). CVSS 7.4 → 9.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-10542",
      "detail": "RESCORED — CVE-2026-10542 (Mattermost). CVSS 5 → 4.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-105742",
      "detail": "RESCORED — CVE-2026-105742 (docling-project docling). CVSS 3.7 → 5.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-105744",
      "detail": "RESCORED — CVE-2026-105744 (docling-project docling). CVSS 7.5 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-105745",
      "detail": "RESCORED — CVE-2026-105745 (docling-project docling). CVSS 6.7 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-105746",
      "detail": "RESCORED — CVE-2026-105746 (docling-project docling). CVSS 2.2 → 5.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-105750",
      "detail": "RESCORED — CVE-2026-105750 (docling-project docling). CVSS 5.9 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-12985",
      "detail": "RESCORED — CVE-2026-12985 (Mattermost). CVSS 6.8 → 9.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-18074",
      "detail": "RESCORED — CVE-2026-18074 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift). CVSS 8.2 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-18095",
      "detail": "RESCORED — CVE-2026-18095 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift). CVSS 8.5 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-18114",
      "detail": "RESCORED — CVE-2026-18114 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift). CVSS 6.5 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-18123",
      "detail": "RESCORED — CVE-2026-18123 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift). CVSS 7.6 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-18131",
      "detail": "RESCORED — CVE-2026-18131 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift). CVSS 8.2 → 6.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-18133",
      "detail": "RESCORED — CVE-2026-18133 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift). CVSS 5.4 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-62874",
      "detail": "RESCORED — CVE-2026-62874 (Microsoft Azure Billing). CVSS 10 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-78446",
      "detail": "RESCORED — CVE-2026-78446 (Microsoft Windows 10 Version 1607). CVSS 5.3 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-78501",
      "detail": "RESCORED — CVE-2026-78501 (Microsoft 365 Copilot's Business Chat). CVSS 7.4 → 8.6 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-90996",
      "detail": "RESCORED — CVE-2026-90996 (Red Hat Enterprise Linux 10). CVSS 4 → 5.5 (NVD)."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2026-39768",
      "detail": "REJECTED — CVE-2026-39768 (CleanTalk Inc Security & Malware scan by CleanTalk). Record withdrawn by the CNA."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-105326",
      "detail": "PATCH SHIPPED — CVE-2026-105326 (Red Hat Hardened Images). Fixed in Red Hat Hardened Images 2.4.19-4.3.hum1."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-42708",
      "detail": "PATCH SHIPPED — CVE-2026-42708 (AF themes WP Post Author). Fixed in WP Post Author 4.0.1."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-57737",
      "detail": "PATCH SHIPPED — CVE-2026-57737 (Averta LTD Shortcodes and extra features for Phlox theme). Fixed in Shortcodes and extra features for Phlox theme 2.17.24."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-85234",
      "detail": "PATCH SHIPPED — CVE-2026-85234 (Red Hat Enterprise Linux 8). Fixed in Red Hat Enterprise Linux 8 0:5.2-28.el8_10."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-106237",
      "detail": "ENRICHED — CVE-2026-106237 (Google Chrome). Received CVSS 9.6 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-106324",
      "detail": "ENRICHED — CVE-2026-106324 (Google Chrome). Received CVSS 6.1 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-106326",
      "detail": "ENRICHED — CVE-2026-106326 (Google Chrome). Received CVSS 4.4 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-63986",
      "detail": "ENRICHED — CVE-2026-63986 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-63990",
      "detail": "ENRICHED — CVE-2026-63990 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-63991",
      "detail": "ENRICHED — CVE-2026-63991 (Linux). Received CVSS 5.5 and CPE data from NVD."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
