{
  "query": {
    "exploited": "1",
    "page": "15"
  },
  "count": 20,
  "total": 1734,
  "page": 15,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T10:45:36.976Z",
    "kev": "2026-10-06T11:44:39.558Z",
    "epss": "2026-10-06T06:57:27.860Z",
    "breaches": "2026-10-06T06:45:27.314Z",
    "posts": "2026-10-06T11:45:39.554Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=15",
    "next": "https://spydr.io/threats.json?exploited=1&page=16"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2025-5086",
      "url": "https://spydr.io/cve/CVE-2025-5086",
      "published": "2025-06-02T18:15:25.010Z",
      "modified": "2026-06-17T09:47:10.400Z",
      "score": 9,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "3ds.com",
      "epss": 0.96915,
      "epss_percentile": 0.99888,
      "exploited": true,
      "kev": {
        "added": "2025-09-11",
        "due": "2025-10-02",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Dassault Systèmes"
      ],
      "products": [
        "Dassault Systèmes DELMIA Apriso"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could lead to a remote code execution."
    },
    {
      "id": "CVE-2025-49113",
      "url": "https://spydr.io/cve/CVE-2025-49113",
      "published": "2025-06-02T05:15:53.420Z",
      "modified": "2026-06-17T09:30:47.027Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.98897,
      "epss_percentile": 0.99927,
      "exploited": true,
      "kev": {
        "added": "2026-02-20",
        "due": "2026-03-13",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Roundcube"
      ],
      "products": [
        "Roundcube Webmail"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization."
    },
    {
      "id": "CVE-2025-48928",
      "url": "https://spydr.io/cve/CVE-2025-48928",
      "published": "2025-05-28T17:15:25.020Z",
      "modified": "2026-06-17T09:30:30.087Z",
      "score": 4,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "score_source": "mitre.org",
      "epss": 0.00553,
      "epss_percentile": 0.4425,
      "exploited": true,
      "kev": {
        "added": "2025-07-01",
        "due": "2025-07-22",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "TeleMessage"
      ],
      "products": [
        "TeleMessage service"
      ],
      "cwes": [
        "CWE-528",
        "CWE-552"
      ],
      "description": "The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a \"core dump\" in which a password previously sent over HTTP would be included in this dump, as exploited in the wild in May 2025."
    },
    {
      "id": "CVE-2025-48927",
      "url": "https://spydr.io/cve/CVE-2025-48927",
      "published": "2025-05-28T17:15:24.837Z",
      "modified": "2026-06-17T09:30:29.883Z",
      "score": 5.3,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "score_source": "mitre.org",
      "epss": 0.11104,
      "epss_percentile": 0.95813,
      "exploited": true,
      "kev": {
        "added": "2025-07-01",
        "due": "2025-07-22",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "TeleMessage"
      ],
      "products": [
        "TeleMessage service"
      ],
      "cwes": [
        "CWE-1188"
      ],
      "description": "The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploited in the wild in May 2025."
    },
    {
      "id": "CVE-2025-34026",
      "url": "https://spydr.io/cve/CVE-2025-34026",
      "published": "2025-05-21T22:15:50.510Z",
      "modified": "2026-06-17T09:13:19.833Z",
      "score": 9.2,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "vulncheck.com",
      "epss": 0.8194,
      "epss_percentile": 0.99643,
      "exploited": true,
      "kev": {
        "added": "2026-01-22",
        "due": "2026-02-12",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Versa"
      ],
      "products": [
        "Versa Concerto"
      ],
      "cwes": [
        "CWE-288"
      ],
      "description": "The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The internal Actuator endpoint can be leveraged for access to heap dumps and trace logs.This issue is known to affect Concerto from 12.1.2 through 12.2.0. Additional versions may be vulnerable."
    },
    {
      "id": "CVE-2025-4008",
      "url": "https://spydr.io/cve/CVE-2025-4008",
      "published": "2025-05-21T16:15:33.987Z",
      "modified": "2026-06-17T09:32:18.077Z",
      "score": 8.7,
      "severity": "high",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "onekey.com",
      "epss": 0.93667,
      "epss_percentile": 0.99842,
      "exploited": true,
      "kev": {
        "added": "2025-10-02",
        "due": "2025-10-23",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Smartbedded"
      ],
      "products": [
        "Smartbedded MeteoBridge"
      ],
      "cwes": [
        "CWE-77",
        "CWE-306"
      ],
      "description": "The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer their meteobridge system through a web application written in CGI shell scripts and C. This web interface exposes an endpoint that is vulnerable to command injection. Remote unauthenticated attackers can gain arbitrary command execution with elevated privileges ( root ) on affected devices."
    },
    {
      "id": "CVE-2025-32709",
      "url": "https://spydr.io/cve/CVE-2025-32709",
      "published": "2025-05-13T17:16:04.020Z",
      "modified": "2026-06-17T09:12:27.700Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.02158,
      "epss_percentile": 0.81561,
      "exploited": true,
      "kev": {
        "added": "2025-05-13",
        "due": "2025-06-03",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally."
    },
    {
      "id": "CVE-2025-32706",
      "url": "https://spydr.io/cve/CVE-2025-32706",
      "published": "2025-05-13T17:16:03.607Z",
      "modified": "2026-06-17T09:12:27.347Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.02313,
      "epss_percentile": 0.82817,
      "exploited": true,
      "kev": {
        "added": "2025-05-13",
        "due": "2025-06-03",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally."
    },
    {
      "id": "CVE-2025-32701",
      "url": "https://spydr.io/cve/CVE-2025-32701",
      "published": "2025-05-13T17:16:02.710Z",
      "modified": "2026-06-17T09:12:26.723Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.01403,
      "epss_percentile": 0.71628,
      "exploited": true,
      "kev": {
        "added": "2025-05-13",
        "due": "2025-06-03",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally."
    },
    {
      "id": "CVE-2025-30400",
      "url": "https://spydr.io/cve/CVE-2025-30400",
      "published": "2025-05-13T17:16:02.537Z",
      "modified": "2026-06-17T09:08:39.300Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.019,
      "epss_percentile": 0.7897,
      "exploited": true,
      "kev": {
        "added": "2025-05-13",
        "due": "2025-06-03",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows Server 2025",
        "Microsoft Windows Server 2025 (Server Core installation)"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Use after free in Windows DWM allows an authorized attacker to elevate privileges locally."
    },
    {
      "id": "CVE-2025-30397",
      "url": "https://spydr.io/cve/CVE-2025-30397",
      "published": "2025-05-13T17:16:02.370Z",
      "modified": "2026-06-17T09:08:38.813Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.26835,
      "epss_percentile": 0.97981,
      "exploited": true,
      "kev": {
        "added": "2025-05-13",
        "due": "2025-06-03",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019"
      ],
      "cwes": [
        "CWE-843"
      ],
      "description": "Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network."
    },
    {
      "id": "CVE-2025-4428",
      "url": "https://spydr.io/cve/CVE-2025-4428",
      "published": "2025-05-13T16:15:32.463Z",
      "modified": "2026-06-17T09:33:13.990Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.86519,
      "epss_percentile": 0.99734,
      "exploited": true,
      "kev": {
        "added": "2025-05-19",
        "due": "2025-06-09",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Ivanti"
      ],
      "products": [
        "Ivanti Endpoint Manager Mobile"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via crafted API requests."
    },
    {
      "id": "CVE-2025-4427",
      "url": "https://spydr.io/cve/CVE-2025-4427",
      "published": "2025-05-13T16:15:32.330Z",
      "modified": "2026-06-17T09:33:13.873Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.99927,
      "epss_percentile": 0.99969,
      "exploited": true,
      "kev": {
        "added": "2025-05-19",
        "due": "2025-06-09",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Ivanti"
      ],
      "products": [
        "Ivanti Endpoint Manager Mobile"
      ],
      "cwes": [
        "CWE-288"
      ],
      "description": "An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the API."
    },
    {
      "id": "CVE-2025-32756",
      "url": "https://spydr.io/cve/CVE-2025-32756",
      "published": "2025-05-13T15:15:57.113Z",
      "modified": "2026-06-17T09:12:32.723Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.29812,
      "epss_percentile": 0.98155,
      "exploited": true,
      "kev": {
        "added": "2025-05-14",
        "due": "2025-06-04",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortinet"
      ],
      "products": [
        "Fortinet FortiNDR",
        "Fortinet FortiCamera",
        "Fortinet FortiRecorder",
        "Fortinet FortiVoice",
        "Fortinet FortiMail"
      ],
      "cwes": [
        "CWE-121",
        "CWE-787"
      ],
      "description": "A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.7, FortiNDR 7.2.0 through 7.2.4, FortiNDR 7.0.0 through 7.0.6, FortiRecorder 7.2.0 through 7.2.3, FortiRecorder 7.0.0 through 7.0.5, FortiRecorder 6.4.0 through 6.4.5, FortiVoice 7.2.0, FortiVoice 7.0.0 through 7.0.6, FortiVoice 6.4.0 through 6.4.10 allows a remote unauthenticated attacker to execute arbitrary code or commands via sending HTTP requests with specially crafted hash cookie."
    },
    {
      "id": "CVE-2025-4632",
      "url": "https://spydr.io/cve/CVE-2025-4632",
      "published": "2025-05-13T06:15:36.537Z",
      "modified": "2026-06-17T09:33:39.023Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.24295,
      "epss_percentile": 0.97803,
      "exploited": true,
      "kev": {
        "added": "2025-05-22",
        "due": "2025-06-12",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Samsung Electronics"
      ],
      "products": [
        "Samsung Electronics MagicINFO 9 Server"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system authority."
    },
    {
      "id": "CVE-2025-42999",
      "url": "https://spydr.io/cve/CVE-2025-42999",
      "published": "2025-05-13T01:15:48.440Z",
      "modified": "2026-08-11T04:17:17.240Z",
      "score": 9.1,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "sap.com",
      "epss": 0.13868,
      "epss_percentile": 0.96427,
      "exploited": true,
      "kev": {
        "added": "2025-05-15",
        "due": "2025-06-05",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "SAP_SE"
      ],
      "products": [
        "SAP_SE SAP NetWeaver (Visual Composer development server)"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system."
    },
    {
      "id": "CVE-2025-47729",
      "url": "https://spydr.io/cve/CVE-2025-47729",
      "published": "2025-05-08T14:15:26.883Z",
      "modified": "2026-06-17T09:28:37.040Z",
      "score": 4.9,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.00447,
      "epss_percentile": 0.36632,
      "exploited": true,
      "kev": {
        "added": "2025-05-12",
        "due": "2025-06-02",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "TeleMessage"
      ],
      "products": [
        "TeleMessage archiving backend"
      ],
      "cwes": [
        "CWE-912"
      ],
      "description": "The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal) app users, which is different functionality than described in the TeleMessage \"End-to-End encryption from the mobile phone through to the corporate archive\" documentation, as exploited in the wild in May 2025."
    },
    {
      "id": "CVE-2025-35939",
      "url": "https://spydr.io/cve/CVE-2025-35939",
      "published": "2025-05-07T23:15:54.103Z",
      "modified": "2026-06-17T09:14:18.460Z",
      "score": 6.9,
      "severity": "medium",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "CNA",
      "epss": 0.01349,
      "epss_percentile": 0.70535,
      "exploited": true,
      "kev": {
        "added": "2025-06-02",
        "due": "2025-06-23",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Craft"
      ],
      "products": [
        "Craft CMS"
      ],
      "cwes": [
        "CWE-472"
      ],
      "description": "Craft CMS stores arbitrary content provided by unauthenticated users in session files. This content could be accessed and executed, possibly using an independent vulnerability. Craft CMS redirects requests that require authentication to the login page and generates a session file on the server at '/var/lib/php/sessions'. Such session files are named 'sess_[session_value]', where '[session_value]' is provided to the client in a 'Set-Cookie' response header. Craft CMS stores the return URL requested by the client without sanitizing parameters. Consequently, an unauthenticated client can introduce arbitrary values, such as PHP code, to a known local file location on the server. Craft CMS versions 5.7.5 and 4.15.3 have been released to address this issue."
    },
    {
      "id": "CVE-2025-2776",
      "url": "https://spydr.io/cve/CVE-2025-2776",
      "published": "2025-05-07T15:15:57.573Z",
      "modified": "2026-06-17T09:07:36.360Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.64726,
      "epss_percentile": 0.99225,
      "exploited": true,
      "kev": {
        "added": "2025-07-22",
        "due": "2025-08-12",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "SysAid"
      ],
      "products": [
        "SysAid On-Prem"
      ],
      "cwes": [
        "CWE-611"
      ],
      "description": "SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives."
    },
    {
      "id": "CVE-2025-2775",
      "url": "https://spydr.io/cve/CVE-2025-2775",
      "published": "2025-05-07T15:15:57.447Z",
      "modified": "2026-06-17T09:07:36.247Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.42612,
      "epss_percentile": 0.98675,
      "exploited": true,
      "kev": {
        "added": "2025-07-22",
        "due": "2025-08-12",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "SysAid"
      ],
      "products": [
        "SysAid On-Prem"
      ],
      "cwes": [
        "CWE-611"
      ],
      "description": "SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionality, allowing for administrator account takeover and file read primitives."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
