{
  "query": {
    "exploited": "1",
    "page": "11"
  },
  "count": 20,
  "total": 1734,
  "page": 11,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T06:45:27.610Z",
    "kev": "2026-10-06T07:44:30.071Z",
    "epss": "2026-10-06T06:57:27.860Z",
    "breaches": "2026-10-06T06:45:27.314Z",
    "posts": "2026-10-06T07:45:30.209Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=11",
    "next": "https://spydr.io/threats.json?exploited=1&page=12"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2025-55182",
      "url": "https://spydr.io/cve/CVE-2025-55182",
      "published": "2025-12-03T16:15:56.463Z",
      "modified": "2026-08-04T05:16:35.063Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "fb.com",
      "epss": 0.99802,
      "epss_percentile": 0.99957,
      "exploited": true,
      "kev": {
        "added": "2025-12-05",
        "due": "2025-12-12",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Meta"
      ],
      "products": [
        "Meta react-server-dom-webpack",
        "Meta react-server-dom-turbopack",
        "Meta react-server-dom-parcel"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints."
    },
    {
      "id": "CVE-2025-62593",
      "url": "https://spydr.io/cve/CVE-2025-62593",
      "published": "2025-11-26T23:15:47.927Z",
      "modified": "2026-10-01T19:17:15.957Z",
      "score": 9.4,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "github.com",
      "epss": 0.62459,
      "epss_percentile": 0.99167,
      "exploited": true,
      "kev": {
        "added": "2026-08-17",
        "due": "2026-08-20",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "ray-project"
      ],
      "products": [
        "ray-project ray"
      ],
      "cwes": [
        "CWE-94",
        "CWE-352"
      ],
      "description": "Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient guard against browser-based attacks, as the current defense uses the User-Agent header starting with the string \"Mozilla\" as a defense mechanism. This defense is insufficient as the fetch specification allows the User-Agent header to be modified. Combined with a DNS rebinding attack against the browser, and this vulnerability is exploitable against a developer running Ray who inadvertently visits a malicious website, or is served a malicious advertisement (malvertising). This issue has been patched in version 2.52.0."
    },
    {
      "id": "CVE-2025-58360",
      "url": "https://spydr.io/cve/CVE-2025-58360",
      "published": "2025-11-25T21:15:56.363Z",
      "modified": "2026-06-17T09:44:21.613Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.60522,
      "epss_percentile": 0.99122,
      "exploited": true,
      "kev": {
        "added": "2025-12-11",
        "due": "2026-01-01",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "geoserver"
      ],
      "products": [
        "geoserver"
      ],
      "cwes": [
        "CWE-611"
      ],
      "description": "GeoServer is an open source server that allows users to share and edit geospatial data. From version 2.26.0 to before 2.26.2 and before 2.25.6, an XML External Entity (XXE) vulnerability was identified. The application accepts XML input through a specific endpoint /geoserver/wms operation GetMap. However, this input is not sufficiently sanitized or restricted, allowing an attacker to define external entities within the XML request. This issue has been patched in GeoServer 2.25.6, GeoServer 2.26.3, and GeoServer 2.27.0."
    },
    {
      "id": "CVE-2025-58034",
      "url": "https://spydr.io/cve/CVE-2025-58034",
      "published": "2025-11-18T17:16:05.057Z",
      "modified": "2026-06-17T09:43:49.303Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "fortinet.com",
      "epss": 0.5558,
      "epss_percentile": 0.99014,
      "exploited": true,
      "kev": {
        "added": "2025-11-18",
        "due": "2025-11-25",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortinet"
      ],
      "products": [
        "Fortinet FortiWeb"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI commands."
    },
    {
      "id": "CVE-2025-13223",
      "url": "https://spydr.io/cve/CVE-2025-13223",
      "published": "2025-11-17T23:15:45.140Z",
      "modified": "2026-07-14T15:21:34.180Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.05026,
      "epss_percentile": 0.92012,
      "exploited": true,
      "kev": {
        "added": "2025-11-19",
        "due": "2025-12-10",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google",
        "Siemens"
      ],
      "products": [
        "Google Chrome",
        "Siemens CADRA"
      ],
      "cwes": [
        "CWE-843"
      ],
      "description": "Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)"
    },
    {
      "id": "CVE-2025-64446",
      "url": "https://spydr.io/cve/CVE-2025-64446",
      "published": "2025-11-14T16:15:58.567Z",
      "modified": "2026-06-17T09:54:23.733Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "fortinet.com",
      "epss": 0.91838,
      "epss_percentile": 0.99815,
      "exploited": true,
      "kev": {
        "added": "2025-11-14",
        "due": "2025-11-21",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortinet"
      ],
      "products": [
        "Fortinet FortiWeb"
      ],
      "cwes": [
        "CWE-23"
      ],
      "description": "A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests."
    },
    {
      "id": "CVE-2025-62215",
      "url": "https://spydr.io/cve/CVE-2025-62215",
      "published": "2025-11-11T18:15:48.920Z",
      "modified": "2026-06-17T09:51:34.350Z",
      "score": 7,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.05985,
      "epss_percentile": 0.93097,
      "exploited": true,
      "kev": {
        "added": "2025-11-12",
        "due": "2025-12-03",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows 11 Version 25H2",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows Server 2025",
        "Microsoft Windows Server 2025 (Server Core installation)"
      ],
      "cwes": [
        "CWE-362",
        "CWE-415"
      ],
      "description": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally."
    },
    {
      "id": "CVE-2025-60710",
      "url": "https://spydr.io/cve/CVE-2025-60710",
      "published": "2025-11-11T18:15:39.073Z",
      "modified": "2026-06-17T09:50:01.133Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.04598,
      "epss_percentile": 0.91383,
      "exploited": true,
      "kev": {
        "added": "2026-04-13",
        "due": "2026-04-27",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows 11 Version 25H2",
        "Microsoft Windows Server 2025",
        "Microsoft Windows Server 2025 (Server Core installation)"
      ],
      "cwes": [
        "CWE-59"
      ],
      "description": "Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally."
    },
    {
      "id": "CVE-2025-12480",
      "url": "https://spydr.io/cve/CVE-2025-12480",
      "published": "2025-11-10T15:15:36.527Z",
      "modified": "2026-06-17T08:32:27.450Z",
      "score": 9.1,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "score_source": "google.com",
      "epss": 0.95428,
      "epss_percentile": 0.99869,
      "exploited": true,
      "kev": {
        "added": "2025-11-12",
        "due": "2025-12-03",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "TrioFox"
      ],
      "products": [
        "TrioFox"
      ],
      "cwes": [
        "CWE-284"
      ],
      "description": "Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after setup is complete."
    },
    {
      "id": "CVE-2025-64328",
      "url": "https://spydr.io/cve/CVE-2025-64328",
      "published": "2025-11-07T04:15:47.397Z",
      "modified": "2026-06-17T15:45:21.527Z",
      "score": 8.6,
      "severity": "high",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "github.com",
      "epss": 0.84618,
      "epss_percentile": 0.99699,
      "exploited": true,
      "kev": {
        "added": "2026-02-03",
        "due": "2026-02-24",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "FreePBX"
      ],
      "products": [
        "FreePBX filestore"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestore module within the Administrative interface is vulnerable to a post-authentication command injection by an authenticated known user via the testconnection -> check_ssh_connect() function. An attacker can leverage this vulnerability to obtain remote access to the system as an asterisk user. This issue is fixed in version 17.0.3."
    },
    {
      "id": "CVE-2023-43000",
      "url": "https://spydr.io/cve/CVE-2023-43000",
      "published": "2025-11-05T19:15:47.937Z",
      "modified": "2026-09-21T18:17:03.620Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.03898,
      "epss_percentile": 0.89951,
      "exploited": true,
      "kev": {
        "added": "2026-03-05",
        "due": "2026-03-26",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple macOS",
        "Apple iOS and iPadOS",
        "Apple Safari"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, Safari 16.6, iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously crafted web content may lead to memory corruption."
    },
    {
      "id": "CVE-2025-11953",
      "url": "https://spydr.io/cve/CVE-2025-11953",
      "published": "2025-11-03T17:15:32.677Z",
      "modified": "2026-06-17T08:31:28.530Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "jfrog.com",
      "epss": 0.9398,
      "epss_percentile": 0.99845,
      "exploited": true,
      "kev": {
        "added": "2026-02-05",
        "due": "2026-02-26",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "react-native-community"
      ],
      "products": [
        "react-native-community react native community cli"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This allows unauthenticated network attackers to send a POST request to the server and run arbitrary executables. On Windows, the attackers can also execute arbitrary shell commands with fully controlled arguments."
    },
    {
      "id": "CVE-2025-61757",
      "url": "https://spydr.io/cve/CVE-2025-61757",
      "published": "2025-10-21T20:20:52.117Z",
      "modified": "2026-06-17T09:50:50.953Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "oracle.com",
      "epss": 0.88647,
      "epss_percentile": 0.99772,
      "exploited": true,
      "kev": {
        "added": "2025-11-21",
        "due": "2025-12-12",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Oracle Corporation"
      ],
      "products": [
        "Oracle Corporation Identity Manager"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Identity Manager. Successful attacks of this vulnerability can result in takeover of Identity Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)."
    },
    {
      "id": "CVE-2025-61932",
      "url": "https://spydr.io/cve/CVE-2025-61932",
      "published": "2025-10-20T08:15:33.303Z",
      "modified": "2026-06-17T09:51:06.030Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "jpcert.or.jp",
      "epss": 0.02768,
      "epss_percentile": 0.85837,
      "exploited": true,
      "kev": {
        "added": "2025-10-22",
        "due": "2025-11-12",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "MOTEX Inc."
      ],
      "products": [
        "MOTEX Inc. Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA))"
      ],
      "cwes": [
        "CWE-940"
      ],
      "description": "Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) improperly verifies the origin of incoming requests, allowing an attacker to execute arbitrary code by sending specially crafted packets."
    },
    {
      "id": "CVE-2025-53521",
      "url": "https://spydr.io/cve/CVE-2025-53521",
      "published": "2025-10-15T14:15:48.377Z",
      "modified": "2026-06-17T09:38:22.483Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "f5.com",
      "epss": 0.02295,
      "epss_percentile": 0.82673,
      "exploited": true,
      "kev": {
        "added": "2026-03-27",
        "due": "2026-03-30",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "F5"
      ],
      "products": [
        "F5 BIG-IP"
      ],
      "cwes": [
        "CWE-121"
      ],
      "description": "When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated."
    },
    {
      "id": "CVE-2025-59287",
      "url": "https://spydr.io/cve/CVE-2025-59287",
      "published": "2025-10-14T17:16:11.670Z",
      "modified": "2026-06-17T09:45:52.480Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.9998,
      "epss_percentile": 0.99981,
      "exploited": true,
      "kev": {
        "added": "2025-10-24",
        "due": "2025-11-14",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows Server 2025",
        "Microsoft Windows Server 2025 (Server Core installation)"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network."
    },
    {
      "id": "CVE-2025-59230",
      "url": "https://spydr.io/cve/CVE-2025-59230",
      "published": "2025-10-14T17:16:04.173Z",
      "modified": "2026-06-17T09:45:46.253Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.02657,
      "epss_percentile": 0.85176,
      "exploited": true,
      "kev": {
        "added": "2025-10-14",
        "due": "2025-11-04",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows 11 Version 25H2",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)"
      ],
      "cwes": [
        "CWE-284"
      ],
      "description": "Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally."
    },
    {
      "id": "CVE-2025-24990",
      "url": "https://spydr.io/cve/CVE-2025-24990",
      "published": "2025-10-14T17:15:39.193Z",
      "modified": "2026-06-17T08:59:56.590Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.06369,
      "epss_percentile": 0.93457,
      "exploited": true,
      "kev": {
        "added": "2025-10-14",
        "due": "2025-11-04",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows 11 Version 25H2",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019"
      ],
      "cwes": [
        "CWE-822"
      ],
      "description": "Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming removal of ltmdm64.sys driver. The driver has been removed in the October cumulative update. Fax modem hardware dependent on this specific driver will no longer work on Windows. Microsoft recommends removing any existing dependencies on this hardware."
    },
    {
      "id": "CVE-2025-39964",
      "url": "https://spydr.io/cve/CVE-2025-39964",
      "published": "2025-10-13T14:15:34.737Z",
      "modified": "2026-09-19T04:17:48.307Z",
      "score": 5.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "score_source": "NVD",
      "epss": 0.01276,
      "epss_percentile": 0.68944,
      "exploited": true,
      "kev": {
        "added": "2026-09-18",
        "due": "2026-09-21",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Linux",
        "Siemens"
      ],
      "products": [
        "Linux",
        "Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
        "Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
        "Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP"
      ],
      "cwes": [
        "CWE-362"
      ],
      "description": "In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal socket state. Disallow this by adding a new ctx->write field that indiciates exclusive ownership for writing."
    },
    {
      "id": "CVE-2025-61884",
      "url": "https://spydr.io/cve/CVE-2025-61884",
      "published": "2025-10-12T03:15:34.720Z",
      "modified": "2026-08-04T05:16:36.407Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "oracle.com",
      "epss": 0.95891,
      "epss_percentile": 0.99873,
      "exploited": true,
      "kev": {
        "added": "2025-10-20",
        "due": "2025-11-10",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Oracle Corporation"
      ],
      "products": [
        "Oracle Corporation Oracle Configurator"
      ],
      "cwes": [
        "CWE-22",
        "CWE-93",
        "CWE-287",
        "CWE-444",
        "CWE-501",
        "CWE-918"
      ],
      "description": "Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Configurator. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Configurator accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
