{
  "query": {
    "exploited": "1",
    "page": "18"
  },
  "count": 20,
  "total": 1734,
  "page": 18,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T12:45:42.157Z",
    "kev": "2026-10-06T13:44:43.860Z",
    "epss": "2026-10-06T12:57:42.533Z",
    "breaches": "2026-10-06T12:45:41.825Z",
    "posts": "2026-10-06T13:45:44.551Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=18",
    "next": "https://spydr.io/threats.json?exploited=1&page=19"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2025-22225",
      "url": "https://spydr.io/cve/CVE-2025-22225",
      "published": "2025-03-04T12:15:33.840Z",
      "modified": "2026-08-04T05:16:33.493Z",
      "score": 8.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.01016,
      "epss_percentile": 0.62068,
      "exploited": true,
      "kev": {
        "added": "2025-03-04",
        "due": "2025-03-25",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "vmware"
      ],
      "products": [
        "VMware ESXi",
        "VMware Cloud Foundation",
        "VMware Telco Cloud Platform",
        "VMware Telco Cloud Infrastructure"
      ],
      "cwes": [
        "CWE-787",
        "CWE-123"
      ],
      "description": "VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox."
    },
    {
      "id": "CVE-2025-22224",
      "url": "https://spydr.io/cve/CVE-2025-22224",
      "published": "2025-03-04T12:15:33.687Z",
      "modified": "2026-06-17T08:45:43.370Z",
      "score": 8.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.01561,
      "epss_percentile": 0.74387,
      "exploited": true,
      "kev": {
        "added": "2025-03-04",
        "due": "2025-03-25",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "VMware"
      ],
      "products": [
        "VMware ESXi",
        "VMware Workstation",
        "VMware Cloud Foundation",
        "VMware Telco Cloud Platform",
        "VMware Telco Cloud Infrastructure"
      ],
      "cwes": [
        "CWE-367"
      ],
      "description": "VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host."
    },
    {
      "id": "CVE-2024-48248",
      "url": "https://spydr.io/cve/CVE-2024-48248",
      "published": "2025-03-04T08:15:33.550Z",
      "modified": "2026-09-24T13:10:00.320Z",
      "score": 8.6,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.94356,
      "epss_percentile": 0.99851,
      "exploited": true,
      "kev": {
        "added": "2025-03-19",
        "due": "2025-04-09",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "NAKIVO"
      ],
      "products": [
        "NAKIVO Backup & Replication Director"
      ],
      "cwes": [
        "CWE-36"
      ],
      "description": "NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to remote code execution across the enterprise because PhysicalDiscovery has cleartext credentials)."
    },
    {
      "id": "CVE-2025-24893",
      "url": "https://spydr.io/cve/CVE-2025-24893",
      "published": "2025-02-20T20:15:46.697Z",
      "modified": "2026-06-17T08:59:47.940Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99864,
      "epss_percentile": 0.99962,
      "exploited": true,
      "kev": {
        "added": "2025-10-30",
        "due": "2025-11-20",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "xwiki"
      ],
      "products": [
        "xwiki-platform"
      ],
      "cwes": [
        "CWE-95",
        "CWE-94"
      ],
      "description": "XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any guest can perform arbitrary remote code execution through a request to `SolrSearch`. This impacts the confidentiality, integrity and availability of the whole XWiki installation. To reproduce on an instance, without being logged in, go to `<host>/xwiki/bin/get/Main/SolrSearch?media=rss&text=%7D%7D%7D%7B%7Basync%20async%3Dfalse%7D%7D%7B%7Bgroovy%7D%7Dprintln%28\"Hello%20from\"%20%2B%20\"%20search%20text%3A\"%20%2B%20%2823%20%2B%2019%29%29%7B%7B%2Fgroovy%7D%7D%7B%7B%2Fasync%7D%7D%20`. If there is an output, and the title of the RSS feed contains `Hello from search text:42`, then the instance is vulnerable. This vulnerability has been patched in XWiki 15.10.11, 16.4.1 and 16.5.0RC1. Users are advised to upgrade. Users unable to upgrade may edit `Main.SolrSearchMacros` in `SolrSearchMacros.xml` on line 955 to match the `rawResponse` macro in `macros.vm#L2824` with a content type of `application/xml`, instead of simply outputting the content of the feed."
    },
    {
      "id": "CVE-2025-24989",
      "url": "https://spydr.io/cve/CVE-2025-24989",
      "published": "2025-02-19T23:15:15.167Z",
      "modified": "2026-06-17T08:59:56.470Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.01622,
      "epss_percentile": 0.75275,
      "exploited": true,
      "kev": {
        "added": "2025-02-21",
        "due": "2025-03-14",
        "action": "Apply mitigations per vendor instructions, follow BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Power Pages"
      ],
      "cwes": [
        "CWE-284"
      ],
      "description": "An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control. This vulnerability has already been mitigated in the service and all affected customers have been notified. This update addressed the registration control bypass. Affected customers have been given instructions on reviewing their sites for potential exploitation and clean up methods. If you've not been notified this vulnerability does not affect you."
    },
    {
      "id": "CVE-2025-0111",
      "url": "https://spydr.io/cve/CVE-2025-0111",
      "published": "2025-02-12T21:15:16.793Z",
      "modified": "2026-06-17T08:25:51.493Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:M/U:Red",
      "score_source": "paloaltonetworks.com",
      "epss": 0.01999,
      "epss_percentile": 0.80028,
      "exploited": true,
      "kev": {
        "added": "2025-02-20",
        "due": "2025-03-13",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Palo Alto Networks"
      ],
      "products": [
        "Palo Alto Networks Cloud NGFW",
        "Palo Alto Networks PAN-OS",
        "Palo Alto Networks Prisma Access"
      ],
      "cwes": [
        "CWE-73",
        "CWE-610"
      ],
      "description": "An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are readable by the “nobody” user. You can greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practices deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue does not affect Cloud NGFW or Prisma Access software."
    },
    {
      "id": "CVE-2025-0108",
      "url": "https://spydr.io/cve/CVE-2025-0108",
      "published": "2025-02-12T21:15:16.290Z",
      "modified": "2026-09-24T13:10:00.320Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:M/U:Red",
      "score_source": "paloaltonetworks.com",
      "epss": 0.98455,
      "epss_percentile": 0.99918,
      "exploited": true,
      "kev": {
        "added": "2025-02-18",
        "due": "2025-03-11",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Palo Alto Networks"
      ],
      "products": [
        "Palo Alto Networks Cloud NGFW",
        "Palo Alto Networks PAN-OS",
        "Palo Alto Networks Prisma Access"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web interface and invoke certain PHP scripts. While invoking these PHP scripts does not enable remote code execution, it can negatively impact integrity and confidentiality of PAN-OS. You can greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practices deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue does not affect Cloud NGFW or Prisma Access software."
    },
    {
      "id": "CVE-2025-21418",
      "url": "https://spydr.io/cve/CVE-2025-21418",
      "published": "2025-02-11T18:15:40.023Z",
      "modified": "2026-06-17T08:43:19.180Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.01568,
      "epss_percentile": 0.74487,
      "exploited": true,
      "kev": {
        "added": "2025-02-11",
        "due": "2025-03-04",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019"
      ],
      "cwes": [
        "CWE-122"
      ],
      "description": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2025-21391",
      "url": "https://spydr.io/cve/CVE-2025-21391",
      "published": "2025-02-11T18:15:37.723Z",
      "modified": "2026-09-24T13:10:00.320Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.02303,
      "epss_percentile": 0.8274,
      "exploited": true,
      "kev": {
        "added": "2025-02-11",
        "due": "2025-03-04",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows Server 2025",
        "Microsoft Windows Server 2025 (Server Core installation)"
      ],
      "cwes": [
        "CWE-59"
      ],
      "description": "Windows Storage Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2025-24472",
      "url": "https://spydr.io/cve/CVE-2025-24472",
      "published": "2025-02-11T17:15:34.867Z",
      "modified": "2026-08-05T05:16:43.473Z",
      "score": 8.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "fortinet.com",
      "epss": 0.07235,
      "epss_percentile": 0.94153,
      "exploited": true,
      "kev": {
        "added": "2025-03-18",
        "due": "2025-04-08",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortinet"
      ],
      "products": [
        "Fortinet FortiOS",
        "Fortinet FortiProxy"
      ],
      "cwes": [
        "CWE-288"
      ],
      "description": "An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior knowledge of upstream and downstream devices serial numbers to gain super-admin privileges on the downstream device, if the Security Fabric is enabled, via crafted CSF proxy requests."
    },
    {
      "id": "CVE-2025-24016",
      "url": "https://spydr.io/cve/CVE-2025-24016",
      "published": "2025-02-10T20:15:42.540Z",
      "modified": "2026-06-17T08:57:53.677Z",
      "score": 9.9,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H",
      "score_source": "github.com",
      "epss": 0.9384,
      "epss_percentile": 0.99843,
      "exploited": true,
      "kev": {
        "added": "2025-06-10",
        "due": "2025-07-01",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "wazuh"
      ],
      "products": [
        "wazuh"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0 and prior to version 4.9.1, an unsafe deserialization vulnerability allows for remote code execution on Wazuh servers. DistributedAPI parameters are a serialized as JSON and deserialized using `as_wazuh_object` (in `framework/wazuh/core/cluster/common.py`). If an attacker manages to inject an unsanitized dictionary in DAPI request/response, they can forge an unhandled exception (`__unhandled_exc__`) to evaluate arbitrary python code. The vulnerability can be triggered by anybody with API access (compromised dashboard or Wazuh servers in the cluster) or, in certain configurations, even by a compromised agent. Version 4.9.1 contains a fix."
    },
    {
      "id": "CVE-2025-24200",
      "url": "https://spydr.io/cve/CVE-2025-24200",
      "published": "2025-02-10T19:15:40.107Z",
      "modified": "2026-06-17T08:58:17.800Z",
      "score": 6.1,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "score_source": "NVD",
      "epss": 0.0442,
      "epss_percentile": 0.91063,
      "exploited": true,
      "kev": {
        "added": "2025-02-12",
        "due": "2025-03-05",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS and iPadOS",
        "Apple iPadOS"
      ],
      "cwes": [
        "CWE-863"
      ],
      "description": "An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5. A physical attack may disable USB Restricted Mode on a locked device. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals."
    },
    {
      "id": "CVE-2025-0994",
      "url": "https://spydr.io/cve/CVE-2025-0994",
      "published": "2025-02-06T16:15:41.493Z",
      "modified": "2026-06-17T08:27:29.190Z",
      "score": 8.6,
      "severity": "high",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "hq.dhs.gov",
      "epss": 0.31085,
      "epss_percentile": 0.98221,
      "exploited": true,
      "kev": {
        "added": "2025-02-07",
        "due": "2025-02-28",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Trimble"
      ],
      "products": [
        "Trimble Cityworks",
        "Trimble Cityworks (with office companion)"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer’s Microsoft Internet Information Services (IIS) web server."
    },
    {
      "id": "CVE-2024-40891",
      "url": "https://spydr.io/cve/CVE-2024-40891",
      "published": "2025-02-04T10:15:08.920Z",
      "modified": "2026-06-17T07:46:48.213Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "zyxel.com.tw",
      "epss": 0.21536,
      "epss_percentile": 0.97558,
      "exploited": true,
      "kev": {
        "added": "2025-02-11",
        "due": "2025-03-04",
        "action": "The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Zyxel"
      ],
      "products": [
        "Zyxel VMG4325-B10A firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device via Telnet."
    },
    {
      "id": "CVE-2024-40890",
      "url": "https://spydr.io/cve/CVE-2024-40890",
      "published": "2025-02-04T10:15:08.717Z",
      "modified": "2026-06-17T07:46:48.077Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "zyxel.com.tw",
      "epss": 0.20703,
      "epss_percentile": 0.97469,
      "exploited": true,
      "kev": {
        "added": "2025-02-11",
        "due": "2025-03-04",
        "action": "The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Zyxel"
      ],
      "products": [
        "Zyxel VMG4325-B10A firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device by sending a crafted HTTP POST request."
    },
    {
      "id": "CVE-2023-52163",
      "url": "https://spydr.io/cve/CVE-2023-52163",
      "published": "2025-02-03T21:15:12.060Z",
      "modified": "2026-06-17T06:42:12.770Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.96921,
      "epss_percentile": 0.99888,
      "exploited": true,
      "kev": {
        "added": "2025-12-22",
        "due": "2026-01-12",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "digiever"
      ],
      "products": [
        "digiever ds-2105 pro firmware"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "Digiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection. NOTE: This vulnerability only affects products that are no longer supported by the maintainer."
    },
    {
      "id": "CVE-2025-25181",
      "url": "https://spydr.io/cve/CVE-2025-25181",
      "published": "2025-02-03T20:15:37.477Z",
      "modified": "2026-06-17T09:00:26.210Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.55549,
      "epss_percentile": 0.99013,
      "exploited": true,
      "kev": {
        "added": "2025-03-10",
        "due": "2025-03-31",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Advantive"
      ],
      "products": [
        "Advantive VeraCore"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "A SQL injection vulnerability in timeoutWarning.asp in Advantive VeraCore through 2025.1.0 allows remote attackers to execute arbitrary SQL commands via the PmSess1 parameter."
    },
    {
      "id": "CVE-2024-57968",
      "url": "https://spydr.io/cve/CVE-2024-57968",
      "published": "2025-02-03T20:15:36.550Z",
      "modified": "2026-06-17T08:14:20.447Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.32284,
      "epss_percentile": 0.98281,
      "exploited": true,
      "kev": {
        "added": "2025-03-10",
        "due": "2025-03-31",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Advantive"
      ],
      "products": [
        "Advantive VeraCore"
      ],
      "cwes": [
        "CWE-434"
      ],
      "description": "Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones that are accessible during web browsing by other users). upload.aspx can be used for this."
    },
    {
      "id": "CVE-2025-24085",
      "url": "https://spydr.io/cve/CVE-2025-24085",
      "published": "2025-01-27T22:15:14.990Z",
      "modified": "2026-06-17T08:58:02.497Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.1751,
      "epss_percentile": 0.97056,
      "exploited": true,
      "kev": {
        "added": "2025-01-29",
        "due": "2025-02-19",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS and iPadOS",
        "Apple iPadOS",
        "Apple macOS",
        "Apple tvOS",
        "Apple visionOS",
        "Apple watchOS"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, visionOS 2.3, watchOS 11.3. A malicious application may be able to elevate privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 17.2."
    },
    {
      "id": "CVE-2025-0411",
      "url": "https://spydr.io/cve/CVE-2025-0411",
      "published": "2025-01-25T05:15:09.533Z",
      "modified": "2026-06-17T08:26:25.627Z",
      "score": 7,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.67071,
      "epss_percentile": 0.99283,
      "exploited": true,
      "kev": {
        "added": "2025-02-06",
        "due": "2025-02-27",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "7-Zip"
      ],
      "products": [
        "7-Zip"
      ],
      "cwes": [
        "CWE-693"
      ],
      "description": "7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of archived files. When extracting files from a crafted archive that bears the Mark-of-the-Web, 7-Zip does not propagate the Mark-of-the-Web to the extracted files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user. Was ZDI-CAN-25456."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
