{
  "query": {
    "exploited": "1",
    "page": "14"
  },
  "count": 20,
  "total": 1734,
  "page": 14,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T10:45:36.976Z",
    "kev": "2026-10-06T10:44:36.922Z",
    "epss": "2026-10-06T06:57:27.860Z",
    "breaches": "2026-10-06T06:45:27.314Z",
    "posts": "2026-10-06T10:45:36.976Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=14",
    "next": "https://spydr.io/threats.json?exploited=1&page=15"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2025-47812",
      "url": "https://spydr.io/cve/CVE-2025-47812",
      "published": "2025-07-10T17:15:47.210Z",
      "modified": "2026-06-17T09:28:43.200Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "mitre.org",
      "epss": 0.93235,
      "epss_percentile": 0.99834,
      "exploited": true,
      "kev": {
        "added": "2025-07-14",
        "due": "2025-08-04",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "wftpserver"
      ],
      "products": [
        "wftpserver Wing FTP Server"
      ],
      "cwes": [
        "CWE-158"
      ],
      "description": "In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\\0' bytes, ultimately allowing injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default). This is thus a remote code execution vulnerability that guarantees a total server compromise. This is also exploitable via anonymous FTP accounts."
    },
    {
      "id": "CVE-2025-48384",
      "url": "https://spydr.io/cve/CVE-2025-48384",
      "published": "2025-07-08T19:15:42.800Z",
      "modified": "2026-09-24T13:10:00.320Z",
      "score": 8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H",
      "score_source": "github.com",
      "epss": 0.042,
      "epss_percentile": 0.90659,
      "exploited": true,
      "kev": {
        "added": "2025-08-25",
        "due": "2025-09-15",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "git"
      ],
      "products": [
        "git"
      ],
      "cwes": [
        "CWE-59",
        "CWE-436"
      ],
      "description": "Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When reading a config value, Git strips any trailing carriage return and line feed (CRLF). When writing a config entry, values with a trailing CR are not quoted, causing the CR to be lost when the config is later read. When initializing a submodule, if the submodule path contains a trailing CR, the altered path is read resulting in the submodule being checked out to an incorrect location. If a symlink exists that points the altered path to the submodule hooks directory, and the submodule contains an executable post-checkout hook, the script may be unintentionally executed after checkout. This vulnerability is fixed in v2.43.7, v2.44.4, v2.45.4, v2.46.4, v2.47.3, v2.48.2, v2.49.1, and v2.50.1."
    },
    {
      "id": "CVE-2025-49706",
      "url": "https://spydr.io/cve/CVE-2025-49706",
      "published": "2025-07-08T17:15:58.250Z",
      "modified": "2026-08-04T05:16:34.723Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
      "score_source": "microsoft.com",
      "epss": 0.99076,
      "epss_percentile": 0.99932,
      "exploited": true,
      "kev": {
        "added": "2025-07-22",
        "due": "2025-07-23",
        "action": "Disconnect public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS) to include SharePoint Server 2013 and earlier versions. For supported versions, please follow the mitigations according to CISA (URL listed below in Notes) and vendor instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft SharePoint Enterprise Server 2016",
        "Microsoft SharePoint Server 2019",
        "Microsoft SharePoint Server Subscription Edition"
      ],
      "cwes": [
        "CWE-287"
      ],
      "description": "Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network."
    },
    {
      "id": "CVE-2025-49704",
      "url": "https://spydr.io/cve/CVE-2025-49704",
      "published": "2025-07-08T17:15:57.867Z",
      "modified": "2026-06-17T09:31:46.077Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.99995,
      "epss_percentile": 0.99988,
      "exploited": true,
      "kev": {
        "added": "2025-07-22",
        "due": "2025-07-23",
        "action": "Disconnect public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS) to include SharePoint Server 2013 and earlier versions. For supported versions, please follow the mitigations according to CISA (URL listed below in Notes) and vendor instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft SharePoint Enterprise Server 2016",
        "Microsoft SharePoint Server 2019"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network."
    },
    {
      "id": "CVE-2025-6554",
      "url": "https://spydr.io/cve/CVE-2025-6554",
      "published": "2025-06-30T22:15:29.873Z",
      "modified": "2026-06-17T10:02:08.217Z",
      "score": 8.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
      "score_source": "CISA ADP",
      "epss": 0.14142,
      "epss_percentile": 0.96477,
      "exploited": true,
      "kev": {
        "added": "2025-07-02",
        "due": "2025-07-23",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-843"
      ],
      "description": "Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)"
    },
    {
      "id": "CVE-2025-32463",
      "url": "https://spydr.io/cve/CVE-2025-32463",
      "published": "2025-06-30T21:15:30.257Z",
      "modified": "2026-06-17T09:12:02.147Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.55498,
      "epss_percentile": 0.99012,
      "exploited": true,
      "kev": {
        "added": "2025-09-29",
        "due": "2025-10-20",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Sudo project"
      ],
      "products": [
        "Sudo project Sudo"
      ],
      "cwes": [
        "CWE-829"
      ],
      "description": "Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option."
    },
    {
      "id": "CVE-2025-20281",
      "url": "https://spydr.io/cve/CVE-2025-20281",
      "published": "2025-06-25T16:15:26.017Z",
      "modified": "2026-06-17T08:41:19.980Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "cisco.com",
      "epss": 0.97601,
      "epss_percentile": 0.99902,
      "exploited": true,
      "kev": {
        "added": "2025-07-28",
        "due": "2025-08-18",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco Identity Services Engine Software"
      ],
      "cwes": [
        "CWE-74"
      ],
      "description": "A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted API request. A successful exploit could allow the attacker to obtain root privileges on an affected device."
    },
    {
      "id": "CVE-2025-6543",
      "url": "https://spydr.io/cve/CVE-2025-6543",
      "published": "2025-06-25T13:15:27.293Z",
      "modified": "2026-06-17T10:02:07.007Z",
      "score": 9.2,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "citrix.com",
      "epss": 0.10562,
      "epss_percentile": 0.95656,
      "exploited": true,
      "kev": {
        "added": "2025-06-30",
        "due": "2025-07-21",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "NetScaler"
      ],
      "products": [
        "NetScaler ADC",
        "NetScaler Gateway"
      ],
      "cwes": [
        "CWE-119"
      ],
      "description": "Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server"
    },
    {
      "id": "CVE-2025-32975",
      "url": "https://spydr.io/cve/CVE-2025-32975",
      "published": "2025-06-24T15:15:23.710Z",
      "modified": "2026-06-17T09:12:53.713Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.02487,
      "epss_percentile": 0.84081,
      "exploited": true,
      "kev": {
        "added": "2026-04-20",
        "due": "2026-05-04",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "quest"
      ],
      "products": [
        "quest kace systems management appliance"
      ],
      "cwes": [
        "CWE-287"
      ],
      "description": "Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) contains an authentication bypass vulnerability that allows attackers to impersonate legitimate users without valid credentials. The vulnerability exists in the SSO authentication handling mechanism and can lead to complete administrative takeover."
    },
    {
      "id": "CVE-2025-48700",
      "url": "https://spydr.io/cve/CVE-2025-48700",
      "published": "2025-06-23T15:15:27.930Z",
      "modified": "2026-06-17T09:30:11.837Z",
      "score": 6.1,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
      "score_source": "CISA ADP",
      "epss": 0.01713,
      "epss_percentile": 0.76591,
      "exploited": true,
      "kev": {
        "added": "2026-04-20",
        "due": "2026-04-23",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "synacor"
      ],
      "products": [
        "synacor zimbra collaboration suite"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Classic UI allows attackers to execute arbitrary JavaScript within the user's session, potentially leading to unauthorized access to sensitive information. This issue arises from insufficient sanitization of HTML content, specifically involving crafted tag structures and attribute values that include an @import directive and other script injection vectors. The vulnerability is triggered when a user views a crafted e-mail message in the Classic UI, requiring no additional user interaction."
    },
    {
      "id": "CVE-2025-6218",
      "url": "https://spydr.io/cve/CVE-2025-6218",
      "published": "2025-06-21T01:15:29.123Z",
      "modified": "2026-06-17T10:01:24.380Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.0",
      "vector": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "trendmicro.com",
      "epss": 0.90479,
      "epss_percentile": 0.99799,
      "exploited": true,
      "kev": {
        "added": "2025-12-09",
        "due": "2025-12-30",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "RARLAB"
      ],
      "products": [
        "RARLAB WinRAR"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of RARLAB WinRAR. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of file paths within archive files. A crafted file path can cause the process to traverse to unintended directories. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-27198."
    },
    {
      "id": "CVE-2025-5777",
      "url": "https://spydr.io/cve/CVE-2025-5777",
      "published": "2025-06-17T13:15:21.523Z",
      "modified": "2026-08-04T05:16:35.613Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "citrix.com",
      "epss": 0.99972,
      "epss_percentile": 0.99978,
      "exploited": true,
      "kev": {
        "added": "2025-07-10",
        "due": "2025-07-11",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "NetScaler"
      ],
      "products": [
        "NetScaler ADC",
        "NetScaler Gateway"
      ],
      "cwes": [
        "CWE-125",
        "CWE-908",
        "CWE-457"
      ],
      "description": "Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server"
    },
    {
      "id": "CVE-2025-43200",
      "url": "https://spydr.io/cve/CVE-2025-43200",
      "published": "2025-06-16T22:16:41.120Z",
      "modified": "2026-09-24T13:10:00.320Z",
      "score": 4.2,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N",
      "score_source": "CISA ADP",
      "epss": 0.01191,
      "epss_percentile": 0.66908,
      "exploited": true,
      "kev": {
        "added": "2025-06-16",
        "due": "2025-07-07",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS and iPadOS",
        "Apple iPadOS",
        "Apple macOS",
        "Apple visionOS",
        "Apple watchOS"
      ],
      "cwes": [],
      "description": "This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5, macOS Sequoia 15.3.1, macOS Sonoma 14.7.4, macOS Ventura 13.7.4, visionOS 2.3.1, watchOS 11.3.1. A logic issue existed when processing a maliciously crafted photo or video shared via an iCloud Link. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals."
    },
    {
      "id": "CVE-2025-33073",
      "url": "https://spydr.io/cve/CVE-2025-33073",
      "published": "2025-06-10T17:23:02.967Z",
      "modified": "2026-06-17T09:13:04.220Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.82699,
      "epss_percentile": 0.9966,
      "exploited": true,
      "kev": {
        "added": "2025-10-20",
        "due": "2025-11-10",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019"
      ],
      "cwes": [
        "CWE-284"
      ],
      "description": "Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network."
    },
    {
      "id": "CVE-2025-33053",
      "url": "https://spydr.io/cve/CVE-2025-33053",
      "published": "2025-06-10T17:22:18.853Z",
      "modified": "2026-06-17T09:13:01.030Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.87015,
      "epss_percentile": 0.99745,
      "exploited": true,
      "kev": {
        "added": "2025-06-10",
        "due": "2025-07-01",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019"
      ],
      "cwes": [
        "CWE-73"
      ],
      "description": "External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network."
    },
    {
      "id": "CVE-2025-47827",
      "url": "https://spydr.io/cve/CVE-2025-47827",
      "published": "2025-06-05T14:15:32.263Z",
      "modified": "2026-06-17T09:28:44.910Z",
      "score": 4.6,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "score_source": "CISA ADP",
      "epss": 0.04927,
      "epss_percentile": 0.91876,
      "exploited": true,
      "kev": {
        "added": "2025-10-14",
        "due": "2025-11-04",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "igel",
        "microsoft"
      ],
      "products": [
        "igel os",
        "microsoft windows 10 1507",
        "microsoft windows 10 1607",
        "microsoft windows 10 1809",
        "microsoft windows 10 21h2",
        "microsoft windows 10 22h2",
        "microsoft windows 11 22h2",
        "microsoft windows 11 23h2",
        "microsoft windows 11 24h2",
        "microsoft windows 11 25h2",
        "microsoft windows server 2012",
        "microsoft windows server 2016",
        "microsoft windows server 2019",
        "microsoft windows server 2022",
        "microsoft windows server 2022 23h2",
        "microsoft windows server 2025"
      ],
      "cwes": [
        "CWE-347"
      ],
      "description": "In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be mounted from an unverified SquashFS image."
    },
    {
      "id": "CVE-2025-21479",
      "url": "https://spydr.io/cve/CVE-2025-21479",
      "published": "2025-06-03T07:15:20.933Z",
      "modified": "2026-06-17T08:43:33.660Z",
      "score": 8.6,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
      "score_source": "qualcomm.com",
      "epss": 0.00843,
      "epss_percentile": 0.56507,
      "exploited": true,
      "kev": {
        "added": "2025-06-03",
        "due": "2025-06-24",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Qualcomm, Inc."
      ],
      "products": [
        "Qualcomm, Inc. Snapdragon"
      ],
      "cwes": [
        "CWE-863"
      ],
      "description": "Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands."
    },
    {
      "id": "CVE-2025-27038",
      "url": "https://spydr.io/cve/CVE-2025-27038",
      "published": "2025-06-03T06:15:27.133Z",
      "modified": "2026-06-17T09:02:48.833Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "qualcomm.com",
      "epss": 0.01016,
      "epss_percentile": 0.62062,
      "exploited": true,
      "kev": {
        "added": "2025-06-03",
        "due": "2025-06-24",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Qualcomm, Inc."
      ],
      "products": [
        "Qualcomm, Inc. Snapdragon"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Memory corruption while rendering graphics using Adreno GPU drivers in Chrome."
    },
    {
      "id": "CVE-2025-21480",
      "url": "https://spydr.io/cve/CVE-2025-21480",
      "published": "2025-06-03T06:15:26.190Z",
      "modified": "2026-06-17T08:43:33.857Z",
      "score": 8.6,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
      "score_source": "qualcomm.com",
      "epss": 0.0046,
      "epss_percentile": 0.37657,
      "exploited": true,
      "kev": {
        "added": "2025-06-03",
        "due": "2025-06-24",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Qualcomm, Inc."
      ],
      "products": [
        "Qualcomm, Inc. Snapdragon"
      ],
      "cwes": [
        "CWE-863"
      ],
      "description": "Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands."
    },
    {
      "id": "CVE-2025-5419",
      "url": "https://spydr.io/cve/CVE-2025-5419",
      "published": "2025-06-03T00:15:21.043Z",
      "modified": "2026-06-17T09:47:52.993Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.07821,
      "epss_percentile": 0.94506,
      "exploited": true,
      "kev": {
        "added": "2025-06-05",
        "due": "2025-06-26",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-125",
        "CWE-787"
      ],
      "description": "Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)"
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
