{
  "query": {
    "exploited": "1",
    "page": "10"
  },
  "count": 20,
  "total": 1734,
  "page": 10,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T06:45:27.610Z",
    "kev": "2026-10-06T07:44:30.071Z",
    "epss": "2026-10-06T06:57:27.860Z",
    "breaches": "2026-10-06T06:45:27.314Z",
    "posts": "2026-10-06T07:45:30.209Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=10",
    "next": "https://spydr.io/threats.json?exploited=1&page=11"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2025-68613",
      "url": "https://spydr.io/cve/CVE-2025-68613",
      "published": "2025-12-19T23:15:52.083Z",
      "modified": "2026-06-17T09:59:20.790Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.98994,
      "epss_percentile": 0.9993,
      "exploited": true,
      "kev": {
        "added": "2026-03-11",
        "due": "2026-03-25",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "n8n-io"
      ],
      "products": [
        "n8n-io n8n"
      ],
      "cwes": [
        "CWE-913"
      ],
      "description": "n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remote Code Execution (RCE) vulnerability in their workflow expression evaluation system. Under certain conditions, expressions supplied by authenticated users during workflow configuration may be evaluated in an execution context that is not sufficiently isolated from the underlying runtime. An authenticated attacker could abuse this behavior to execute arbitrary code with the privileges of the n8n process. Successful exploitation may lead to full compromise of the affected instance, including unauthorized access to sensitive data, modification of workflows, and execution of system-level operations. This issue has been fixed in versions 1.120.4, 1.121.1, and 1.122.0. Users are strongly advised to upgrade to a patched version, which introduces additional safeguards to restrict expression evaluation. If upgrading is not immediately possible, administrators should consider the following temporary mitigations: Limit workflow creation and editing permissions to fully trusted users only; and/or deploy n8n in a hardened environment with restricted operating system privileges and network access to reduce the impact of potential exploitation. These workarounds do not fully eliminate the risk and should only be used as short-term measures."
    },
    {
      "id": "CVE-2025-14847",
      "url": "https://spydr.io/cve/CVE-2025-14847",
      "published": "2025-12-19T11:15:49.277Z",
      "modified": "2026-06-17T08:36:38.717Z",
      "score": 8.7,
      "severity": "high",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "mongodb.com",
      "epss": 0.83218,
      "epss_percentile": 0.99672,
      "exploited": true,
      "kev": {
        "added": "2025-12-29",
        "due": "2026-01-19",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "MongoDB Inc."
      ],
      "products": [
        "MongoDB Inc. MongoDB Server"
      ],
      "cwes": [
        "CWE-130"
      ],
      "description": "Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater than or equal to 3.6.0."
    },
    {
      "id": "CVE-2025-14733",
      "url": "https://spydr.io/cve/CVE-2025-14733",
      "published": "2025-12-19T01:16:05.530Z",
      "modified": "2026-09-09T04:17:52.700Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Red",
      "score_source": "CNA",
      "epss": 0.2651,
      "epss_percentile": 0.97959,
      "exploited": true,
      "kev": {
        "added": "2025-12-19",
        "due": "2025-12-26",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "WatchGuard"
      ],
      "products": [
        "WatchGuard Fireware OS"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer. If the Firebox was previously configured with the mobile user VPN with IKEv2 or a branch office VPN using IKEv2 to a dynamic gateway peer, and both of those configurations have since been deleted, that Firebox may still be vulnerable if a branch office VPN to a static gateway peer is still configured."
    },
    {
      "id": "CVE-2025-40602",
      "url": "https://spydr.io/cve/CVE-2025-40602",
      "published": "2025-12-18T11:15:46.760Z",
      "modified": "2026-06-17T09:21:49.277Z",
      "score": 6.6,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.02756,
      "epss_percentile": 0.85767,
      "exploited": true,
      "kev": {
        "added": "2025-12-17",
        "due": "2025-12-24",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "SonicWall"
      ],
      "products": [
        "SonicWall SMA1000"
      ],
      "cwes": [
        "CWE-250",
        "CWE-862"
      ],
      "description": "A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC)."
    },
    {
      "id": "CVE-2025-68461",
      "url": "https://spydr.io/cve/CVE-2025-68461",
      "published": "2025-12-18T05:15:56.623Z",
      "modified": "2026-06-17T09:59:06.300Z",
      "score": 6.1,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.26842,
      "epss_percentile": 0.97981,
      "exploited": true,
      "kev": {
        "added": "2026-02-20",
        "due": "2026-03-13",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Roundcube"
      ],
      "products": [
        "Roundcube Webmail"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document."
    },
    {
      "id": "CVE-2025-43529",
      "url": "https://spydr.io/cve/CVE-2025-43529",
      "published": "2025-12-17T21:16:11.570Z",
      "modified": "2026-09-30T20:10:00.247Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.08763,
      "epss_percentile": 0.95026,
      "exploited": true,
      "kev": {
        "added": "2025-12-15",
        "due": "2026-01-05",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple Safari",
        "Apple iOS and iPadOS",
        "Apple macOS",
        "Apple tvOS",
        "Apple visionOS",
        "Apple watchOS"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 was also issued in response to this report."
    },
    {
      "id": "CVE-2025-20393",
      "url": "https://spydr.io/cve/CVE-2025-20393",
      "published": "2025-12-17T17:15:48.523Z",
      "modified": "2026-06-17T08:41:39.983Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "cisco.com",
      "epss": 0.32392,
      "epss_percentile": 0.98289,
      "exploited": true,
      "kev": {
        "added": "2025-12-17",
        "due": "2025-12-24",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco Secure Email",
        "Cisco Secure Email and Web Manager"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to execute arbitrary system commands on an affected device with root privileges. This vulnerability is due to insufficient validation of HTTP requests by the Spam Quarantine feature. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with&nbsp;root privileges."
    },
    {
      "id": "CVE-2025-59374",
      "url": "https://spydr.io/cve/CVE-2025-59374",
      "published": "2025-12-17T05:16:13.080Z",
      "modified": "2026-09-25T23:10:00.463Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "CNA",
      "epss": 0.01197,
      "epss_percentile": 0.67061,
      "exploited": true,
      "kev": {
        "added": "2025-12-17",
        "due": "2026-01-07",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "ASUS"
      ],
      "products": [
        "ASUS live update"
      ],
      "cwes": [
        "CWE-506"
      ],
      "description": "\"UNSUPPORTED WHEN ASSIGNED\" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting conditions to perform unintended actions. Only devices that met these conditions and installed the compromised versions were affected. The Live Update client has already reached End-of-Support (EOS) in October 2021, and no currently supported devices or products are affected by this issue."
    },
    {
      "id": "CVE-2025-37164",
      "url": "https://spydr.io/cve/CVE-2025-37164",
      "published": "2025-12-16T17:16:07.843Z",
      "modified": "2026-06-17T09:15:17.283Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.90193,
      "epss_percentile": 0.99796,
      "exploited": true,
      "kev": {
        "added": "2026-01-07",
        "due": "2026-01-28",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Hewlett Packard Enterprise (HPE)"
      ],
      "products": [
        "Hewlett Packard Enterprise (HPE) HPE OneView"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "A remote code execution issue exists in HPE OneView."
    },
    {
      "id": "CVE-2025-43520",
      "url": "https://spydr.io/cve/CVE-2025-43520",
      "published": "2025-12-12T21:15:56.830Z",
      "modified": "2026-09-30T20:10:00.247Z",
      "score": 5.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "score_source": "NVD",
      "epss": 0.00425,
      "epss_percentile": 0.3458,
      "exploited": true,
      "kev": {
        "added": "2026-03-20",
        "due": "2026-04-03",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS and iPadOS",
        "Apple macOS",
        "Apple tvOS",
        "Apple visionOS",
        "Apple watchOS"
      ],
      "cwes": [
        "CWE-120"
      ],
      "description": "A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious application may be able to cause unexpected system termination or write kernel memory."
    },
    {
      "id": "CVE-2025-43510",
      "url": "https://spydr.io/cve/CVE-2025-43510",
      "published": "2025-12-12T21:15:55.843Z",
      "modified": "2026-09-30T20:10:00.247Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.00355,
      "epss_percentile": 0.27007,
      "exploited": true,
      "kev": {
        "added": "2026-03-20",
        "due": "2026-04-03",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS and iPadOS",
        "Apple macOS",
        "Apple tvOS",
        "Apple visionOS",
        "Apple watchOS"
      ],
      "cwes": [
        "CWE-667"
      ],
      "description": "A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious application may cause unexpected changes in memory shared between processes."
    },
    {
      "id": "CVE-2025-14611",
      "url": "https://spydr.io/cve/CVE-2025-14611",
      "published": "2025-12-12T21:15:53.107Z",
      "modified": "2026-06-17T08:36:15.740Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "CNA",
      "epss": 0.53302,
      "epss_percentile": 0.98956,
      "exploited": true,
      "kev": {
        "added": "2025-12-15",
        "due": "2026-01-05",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Gladinet"
      ],
      "products": [
        "Gladinet CentreStack and TrioFox"
      ],
      "cwes": [
        "CWE-798"
      ],
      "description": "Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degrades security for public exposed endpoints that may make use of it and may offer arbitrary local file inclusion when provided a specially crafted request without authentication. This opens the door for future exploitation and can be leveraged with previous vulnerabilities to gain a full system compromise."
    },
    {
      "id": "CVE-2025-14174",
      "url": "https://spydr.io/cve/CVE-2025-14174",
      "published": "2025-12-12T20:15:39.663Z",
      "modified": "2026-09-30T16:10:00.223Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.22327,
      "epss_percentile": 0.97626,
      "exploited": true,
      "kev": {
        "added": "2025-12-12",
        "due": "2026-01-02",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-787",
        "CWE-119"
      ],
      "description": "Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)"
    },
    {
      "id": "CVE-2025-8110",
      "url": "https://spydr.io/cve/CVE-2025-8110",
      "published": "2025-12-10T14:16:19.847Z",
      "modified": "2026-06-17T10:06:19.407Z",
      "score": 8.7,
      "severity": "high",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:X/U:X",
      "score_source": "CNA",
      "epss": 0.85202,
      "epss_percentile": 0.99711,
      "exploited": true,
      "kev": {
        "added": "2026-01-12",
        "due": "2026-02-02",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Gogs"
      ],
      "products": [
        "Gogs"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code."
    },
    {
      "id": "CVE-2025-62221",
      "url": "https://spydr.io/cve/CVE-2025-62221",
      "published": "2025-12-09T18:15:56.517Z",
      "modified": "2026-09-25T23:10:00.463Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.02505,
      "epss_percentile": 0.84192,
      "exploited": true,
      "kev": {
        "added": "2025-12-09",
        "due": "2025-12-30",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows 11 Version 25H2",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows Server 2025",
        "Microsoft Windows Server 2025 (Server Core installation)"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally."
    },
    {
      "id": "CVE-2025-59718",
      "url": "https://spydr.io/cve/CVE-2025-59718",
      "published": "2025-12-09T18:15:54.983Z",
      "modified": "2026-06-17T09:46:35.807Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "fortinet.com",
      "epss": 0.68293,
      "epss_percentile": 0.99315,
      "exploited": true,
      "kev": {
        "added": "2025-12-16",
        "due": "2025-12-23",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortinet",
        "Siemens"
      ],
      "products": [
        "Fortinet FortiSwitchManager",
        "Fortinet FortiOS",
        "Fortinet FortiProxy",
        "Siemens RUGGEDCOM APE1808"
      ],
      "cwes": [
        "CWE-347"
      ],
      "description": "A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0.0 through 7.0.21, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message."
    },
    {
      "id": "CVE-2025-48633",
      "url": "https://spydr.io/cve/CVE-2025-48633",
      "published": "2025-12-08T17:16:19.610Z",
      "modified": "2026-09-30T16:10:00.223Z",
      "score": 5.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.00262,
      "epss_percentile": 0.16382,
      "exploited": true,
      "kev": {
        "added": "2025-12-02",
        "due": "2025-12-23",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Android"
      ],
      "cwes": [],
      "description": "In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation."
    },
    {
      "id": "CVE-2025-48572",
      "url": "https://spydr.io/cve/CVE-2025-48572",
      "published": "2025-12-08T17:16:15.003Z",
      "modified": "2026-09-30T16:10:00.223Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.00259,
      "epss_percentile": 0.1599,
      "exploited": true,
      "kev": {
        "added": "2025-12-02",
        "due": "2025-12-23",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Android"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation."
    },
    {
      "id": "CVE-2025-34291",
      "url": "https://spydr.io/cve/CVE-2025-34291",
      "published": "2025-12-05T23:15:47.433Z",
      "modified": "2026-07-14T23:17:22.617Z",
      "score": 9.4,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "vulncheck.com",
      "epss": 0.92808,
      "epss_percentile": 0.99828,
      "exploited": true,
      "kev": {
        "added": "2026-05-21",
        "due": "2026-06-04",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Langflow"
      ],
      "products": [
        "Langflow"
      ],
      "cwes": [
        "CWE-346"
      ],
      "description": "Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with allow_credentials=True) combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. An attacker-controlled origin can therefore obtain fresh access_token / refresh_token pairs for a victim session. Obtained tokens permit access to authenticated endpoints — including built-in code-execution functionality — allowing the attacker to execute arbitrary code and achieve full system compromise."
    },
    {
      "id": "CVE-2025-66644",
      "url": "https://spydr.io/cve/CVE-2025-66644",
      "published": "2025-12-05T19:15:53.293Z",
      "modified": "2026-06-17T09:57:08.520Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.03415,
      "epss_percentile": 0.88517,
      "exploited": true,
      "kev": {
        "added": "2025-12-08",
        "due": "2025-12-29",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Array Networks"
      ],
      "products": [
        "Array Networks ArrayOS AG"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
