{
  "query": {
    "exploited": "1",
    "page": "13"
  },
  "count": 20,
  "total": 1734,
  "page": 13,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T08:45:32.201Z",
    "kev": "2026-10-06T09:44:34.321Z",
    "epss": "2026-10-06T06:57:27.860Z",
    "breaches": "2026-10-06T06:45:27.314Z",
    "posts": "2026-10-06T09:45:34.451Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=13",
    "next": "https://spydr.io/threats.json?exploited=1&page=14"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2025-57819",
      "url": "https://spydr.io/cve/CVE-2025-57819",
      "published": "2025-08-28T17:15:36.790Z",
      "modified": "2026-09-26T00:10:00.127Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "github.com",
      "epss": 0.85463,
      "epss_percentile": 0.99717,
      "exploited": true,
      "kev": {
        "added": "2025-08-29",
        "due": "2025-09-19",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "FreePBX"
      ],
      "products": [
        "FreePBX endpoint"
      ],
      "cwes": [
        "CWE-89",
        "CWE-288"
      ],
      "description": "FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and remote code execution. This issue has been patched in endpoint versions 15.0.66, 16.0.89, and 17.0.3."
    },
    {
      "id": "CVE-2025-7775",
      "url": "https://spydr.io/cve/CVE-2025-7775",
      "published": "2025-08-26T13:15:32.870Z",
      "modified": "2026-06-17T10:05:38.060Z",
      "score": 9.2,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "citrix.com",
      "epss": 0.20284,
      "epss_percentile": 0.97408,
      "exploited": true,
      "kev": {
        "added": "2025-08-26",
        "due": "2025-08-28",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "NetScaler"
      ],
      "products": [
        "NetScaler ADC",
        "NetScaler Gateway"
      ],
      "cwes": [
        "CWE-119"
      ],
      "description": "Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server (OR) NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB virtual servers of type (HTTP, SSL or HTTP_QUIC) bound with IPv6 services or servicegroups bound with IPv6 servers (OR) NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB virtual servers of type (HTTP, SSL or HTTP_QUIC) bound with DBS IPv6 services or servicegroups bound with IPv6 DBS servers (OR) CR virtual server with type HDX"
    },
    {
      "id": "CVE-2025-43300",
      "url": "https://spydr.io/cve/CVE-2025-43300",
      "published": "2025-08-21T01:15:36.243Z",
      "modified": "2026-06-17T09:23:42.063Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.32498,
      "epss_percentile": 0.98295,
      "exploited": true,
      "kev": {
        "added": "2025-08-21",
        "due": "2025-09-11",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS and iPadOS",
        "Apple iPadOS",
        "Apple macOS"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 and iPadOS 16.7.12, iOS 18.6.2 and iPadOS 18.6.2, iPadOS 17.7.10, macOS Sequoia 15.6.1, macOS Sonoma 14.7.8, macOS Ventura 13.7.8. Processing a malicious image file may result in memory corruption. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals."
    },
    {
      "id": "CVE-2025-8876",
      "url": "https://spydr.io/cve/CVE-2025-8876",
      "published": "2025-08-14T15:15:43.170Z",
      "modified": "2026-06-17T10:07:50.067Z",
      "score": 9.4,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "CNA",
      "epss": 0.03448,
      "epss_percentile": 0.88633,
      "exploited": true,
      "kev": {
        "added": "2025-08-13",
        "due": "2025-08-20",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "N-able"
      ],
      "products": [
        "N-able N-central"
      ],
      "cwes": [
        "CWE-20",
        "CWE-78"
      ],
      "description": "Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-central: before 2025.3.1."
    },
    {
      "id": "CVE-2025-8875",
      "url": "https://spydr.io/cve/CVE-2025-8875",
      "published": "2025-08-14T15:15:43.020Z",
      "modified": "2026-09-24T13:10:00.320Z",
      "score": 9.4,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "CNA",
      "epss": 0.01899,
      "epss_percentile": 0.78959,
      "exploited": true,
      "kev": {
        "added": "2025-08-13",
        "due": "2025-08-20",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "N-able"
      ],
      "products": [
        "N-able N-central"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-central: before 2025.3.1."
    },
    {
      "id": "CVE-2025-8088",
      "url": "https://spydr.io/cve/CVE-2025-8088",
      "published": "2025-08-08T12:15:29.343Z",
      "modified": "2026-08-11T04:17:18.587Z",
      "score": 8.4,
      "severity": "high",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "eset.com",
      "epss": 0.94051,
      "epss_percentile": 0.99846,
      "exploited": true,
      "kev": {
        "added": "2025-08-12",
        "due": "2025-09-02",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "win.rar GmbH"
      ],
      "products": [
        "win.rar GmbH WinRAR"
      ],
      "cwes": [
        "CWE-35"
      ],
      "description": "A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET."
    },
    {
      "id": "CVE-2025-54253",
      "url": "https://spydr.io/cve/CVE-2025-54253",
      "published": "2025-08-05T17:15:29.283Z",
      "modified": "2026-06-17T09:39:43.257Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "adobe.com",
      "epss": 0.88262,
      "epss_percentile": 0.99767,
      "exploited": true,
      "kev": {
        "added": "2025-10-15",
        "due": "2025-11-05",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Adobe"
      ],
      "products": [
        "Adobe Experience Manager"
      ],
      "cwes": [
        "CWE-863"
      ],
      "description": "Adobe Experience Manager versions 6.5.23 and earlier are affected by a Misconfiguration vulnerability that could result in arbitrary code execution. An attacker could leverage this vulnerability to bypass security mechanisms and execute code. Exploitation of this issue does not require user interaction and scope is changed."
    },
    {
      "id": "CVE-2025-54948",
      "url": "https://spydr.io/cve/CVE-2025-54948",
      "published": "2025-08-05T13:15:28.487Z",
      "modified": "2026-06-17T09:40:58.740Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.23919,
      "epss_percentile": 0.97773,
      "exploited": true,
      "kev": {
        "added": "2025-08-18",
        "due": "2025-09-08",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Trend Micro, Inc."
      ],
      "products": [
        "Trend Micro, Inc. Trend Micro Apex One"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations."
    },
    {
      "id": "CVE-2025-6205",
      "url": "https://spydr.io/cve/CVE-2025-6205",
      "published": "2025-08-04T10:15:28.057Z",
      "modified": "2026-06-17T10:01:22.973Z",
      "score": 9.1,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "score_source": "3ds.com",
      "epss": 0.73752,
      "epss_percentile": 0.99465,
      "exploited": true,
      "kev": {
        "added": "2025-10-28",
        "due": "2025-11-18",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Dassault Systèmes"
      ],
      "products": [
        "Dassault Systèmes DELMIA Apriso"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "A missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to gain privileged access to the application."
    },
    {
      "id": "CVE-2025-6204",
      "url": "https://spydr.io/cve/CVE-2025-6204",
      "published": "2025-08-04T10:15:27.800Z",
      "modified": "2026-06-17T10:01:22.863Z",
      "score": 8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "3ds.com",
      "epss": 0.79342,
      "epss_percentile": 0.99593,
      "exploited": true,
      "kev": {
        "added": "2025-10-28",
        "due": "2025-11-18",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Dassault Systèmes"
      ],
      "products": [
        "Dassault Systèmes DELMIA Apriso"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "An Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to execute arbitrary code."
    },
    {
      "id": "CVE-2025-31277",
      "url": "https://spydr.io/cve/CVE-2025-31277",
      "published": "2025-07-30T00:15:30.830Z",
      "modified": "2026-09-21T17:17:25.950Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.01604,
      "epss_percentile": 0.75007,
      "exploited": true,
      "kev": {
        "added": "2026-03-20",
        "due": "2026-04-03",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple",
        "Red Hat"
      ],
      "products": [
        "Apple Safari",
        "Apple iOS and iPadOS",
        "Apple macOS",
        "Apple tvOS",
        "Apple visionOS",
        "Apple watchOS",
        "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "Red Hat Enterprise Linux 8",
        "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "Red Hat Enterprise Linux 9",
        "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "Red Hat Enterprise Linux 9.4 Extended Update Support"
      ],
      "cwes": [
        "CWE-119",
        "CWE-120"
      ],
      "description": "The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption."
    },
    {
      "id": "CVE-2025-38352",
      "url": "https://spydr.io/cve/CVE-2025-38352",
      "published": "2025-07-22T08:15:23.577Z",
      "modified": "2026-09-08T18:17:32.447Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "CNA",
      "epss": 0.01289,
      "epss_percentile": 0.69216,
      "exploited": true,
      "kev": {
        "added": "2025-09-04",
        "due": "2025-09-25",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Linux"
      ],
      "products": [
        "Linux"
      ],
      "cwes": [
        "CWE-367"
      ],
      "description": "In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() If an exiting non-autoreaping task has already passed exit_notify() and calls handle_posix_cpu_timers() from IRQ, it can be reaped by its parent or debugger right after unlock_task_sighand(). If a concurrent posix_cpu_timer_del() runs at that moment, it won't be able to detect timer->it.cpu.firing != 0: cpu_timer_task_rcu() and/or lock_task_sighand() will fail. Add the tsk->exit_state check into run_posix_cpu_timers() to fix this. This fix is not needed if CONFIG_POSIX_CPU_TIMERS_TASK_WORK=y, because exit_task_work() is called before exit_notify(). But the check still makes sense, task_work_add(&tsk->posix_cputimers_work.work) will fail anyway in this case."
    },
    {
      "id": "CVE-2025-53770",
      "url": "https://spydr.io/cve/CVE-2025-53770",
      "published": "2025-07-20T01:15:30.777Z",
      "modified": "2026-08-04T05:16:34.887Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.99998,
      "epss_percentile": 0.99991,
      "exploited": true,
      "kev": {
        "added": "2025-07-20",
        "due": "2025-07-21",
        "action": "Disconnect public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS) to include SharePoint Server 2013 and earlier versions. For supported versions, please follow the mitigations according to CISA (URL listed below in Notes) and vendor instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft SharePoint Enterprise Server 2016",
        "Microsoft SharePoint Server 2019",
        "Microsoft SharePoint Server Subscription Edition"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the meantime, please make sure that the mitigation provided in this CVE documentation is in place so that you are protected from exploitation."
    },
    {
      "id": "CVE-2025-54313",
      "url": "https://spydr.io/cve/CVE-2025-54313",
      "published": "2025-07-19T17:15:23.733Z",
      "modified": "2026-06-17T09:39:49.897Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N",
      "score_source": "mitre.org",
      "epss": 0.04522,
      "epss_percentile": 0.91249,
      "exploited": true,
      "kev": {
        "added": "2026-01-22",
        "due": "2026-02-12",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "prettier"
      ],
      "products": [
        "prettier eslint-config-prettier"
      ],
      "cwes": [
        "CWE-506"
      ],
      "description": "eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows."
    },
    {
      "id": "CVE-2025-54309",
      "url": "https://spydr.io/cve/CVE-2025-54309",
      "published": "2025-07-18T19:15:25.353Z",
      "modified": "2026-06-17T09:39:49.643Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.94905,
      "epss_percentile": 0.99859,
      "exploited": true,
      "kev": {
        "added": "2025-07-22",
        "due": "2025-08-12",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "CrushFTP"
      ],
      "products": [
        "CrushFTP"
      ],
      "cwes": [
        "CWE-420"
      ],
      "description": "CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS, as exploited in the wild in July 2025."
    },
    {
      "id": "CVE-2025-54068",
      "url": "https://spydr.io/cve/CVE-2025-54068",
      "published": "2025-07-17T19:15:25.470Z",
      "modified": "2026-06-17T09:39:21.790Z",
      "score": 9.2,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "github.com",
      "epss": 0.97072,
      "epss_percentile": 0.99892,
      "exploited": true,
      "kev": {
        "added": "2026-03-20",
        "due": "2026-04-03",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "livewire"
      ],
      "products": [
        "livewire"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnerability allows unauthenticated attackers to achieve remote command execution in specific scenarios. The issue stems from how certain component property updates are hydrated. This vulnerability is unique to Livewire v3 and does not affect prior major versions. Exploitation requires a component to be mounted and configured in a particular way, but does not require authentication or user interaction. This issue has been patched in Livewire v3.6.4. All users are strongly encouraged to upgrade to this version or later as soon as possible. No known workarounds are available."
    },
    {
      "id": "CVE-2025-25257",
      "url": "https://spydr.io/cve/CVE-2025-25257",
      "published": "2025-07-17T16:15:34.723Z",
      "modified": "2026-06-17T09:00:34.647Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99775,
      "epss_percentile": 0.99954,
      "exploited": true,
      "kev": {
        "added": "2025-07-18",
        "due": "2025-08-08",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortinet"
      ],
      "products": [
        "Fortinet FortiWeb"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.7, FortiWeb 7.2.0 through 7.2.10, FortiWeb 7.0.0 through 7.0.10 allows an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests."
    },
    {
      "id": "CVE-2025-20337",
      "url": "https://spydr.io/cve/CVE-2025-20337",
      "published": "2025-07-16T17:15:30.573Z",
      "modified": "2026-06-17T08:41:29.520Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "cisco.com",
      "epss": 0.67825,
      "epss_percentile": 0.99302,
      "exploited": true,
      "kev": {
        "added": "2025-07-28",
        "due": "2025-08-18",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco Identity Services Engine Software",
        "Cisco ISE Passive Identity Connector"
      ],
      "cwes": [
        "CWE-74"
      ],
      "description": "A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted API request. A successful exploit could allow the attacker to obtain root privileges on an affected device."
    },
    {
      "id": "CVE-2025-6558",
      "url": "https://spydr.io/cve/CVE-2025-6558",
      "published": "2025-07-15T18:15:24.533Z",
      "modified": "2026-10-01T12:00:53.397Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.09464,
      "epss_percentile": 0.95295,
      "exploited": true,
      "kev": {
        "added": "2025-07-22",
        "due": "2025-08-12",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)"
    },
    {
      "id": "CVE-2025-47813",
      "url": "https://spydr.io/cve/CVE-2025-47813",
      "published": "2025-07-10T17:15:47.403Z",
      "modified": "2026-06-17T09:28:43.333Z",
      "score": 4.3,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
      "score_source": "mitre.org",
      "epss": 0.63107,
      "epss_percentile": 0.99184,
      "exploited": true,
      "kev": {
        "added": "2026-03-16",
        "due": "2026-03-30",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "wftpserver"
      ],
      "products": [
        "wftpserver Wing FTP Server"
      ],
      "cwes": [
        "CWE-209"
      ],
      "description": "loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
