{
  "query": {
    "exploited": "1",
    "page": "19"
  },
  "count": 20,
  "total": 1734,
  "page": 19,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T14:45:46.442Z",
    "kev": "2026-10-06T14:44:46.299Z",
    "epss": "2026-10-06T12:57:42.533Z",
    "breaches": "2026-10-06T12:45:41.825Z",
    "posts": "2026-10-06T14:45:46.442Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=19",
    "next": "https://spydr.io/threats.json?exploited=1&page=20"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2025-23006",
      "url": "https://spydr.io/cve/CVE-2025-23006",
      "published": "2025-01-23T12:15:28.523Z",
      "modified": "2026-09-24T13:10:00.320Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.23432,
      "epss_percentile": 0.97732,
      "exploited": true,
      "kev": {
        "added": "2025-01-24",
        "due": "2025-02-14",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "SonicWall"
      ],
      "products": [
        "SonicWall SMA1000"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote unauthenticated attacker to execute arbitrary OS commands."
    },
    {
      "id": "CVE-2025-23209",
      "url": "https://spydr.io/cve/CVE-2025-23209",
      "published": "2025-01-18T01:15:07.633Z",
      "modified": "2026-06-17T08:52:39.483Z",
      "score": 8.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.21776,
      "epss_percentile": 0.97578,
      "exploited": true,
      "kev": {
        "added": "2025-02-20",
        "due": "2025-03-13",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "craftcms"
      ],
      "products": [
        "craftcms cms"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. This is an remote code execution (RCE) vulnerability that affects Craft 4 and 5 installs where your security key has already been compromised. Anyone running an unpatched version of Craft with a compromised security key is affected. This vulnerability has been patched in Craft 5.5.8 and 4.13.8. Users who cannot update to a patched version, should rotate their security keys and ensure their privacy to help migitgate the issue."
    },
    {
      "id": "CVE-2024-57728",
      "url": "https://spydr.io/cve/CVE-2024-57728",
      "published": "2025-01-15T23:15:09.777Z",
      "modified": "2026-06-17T08:13:58.993Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.64664,
      "epss_percentile": 0.99223,
      "exploited": true,
      "kev": {
        "added": "2026-04-24",
        "due": "2026-05-08",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "simple-help"
      ],
      "products": [
        "simple-help simplehelp"
      ],
      "cwes": [
        "CWE-59",
        "CWE-22"
      ],
      "description": "SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user."
    },
    {
      "id": "CVE-2024-57727",
      "url": "https://spydr.io/cve/CVE-2024-57727",
      "published": "2025-01-15T23:15:09.650Z",
      "modified": "2026-08-04T05:16:31.913Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.96576,
      "epss_percentile": 0.99882,
      "exploited": true,
      "kev": {
        "added": "2025-02-13",
        "due": "2025-03-06",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "simple-help"
      ],
      "products": [
        "simple-help simplehelp"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files include server configuration files containing various secrets and hashed user passwords."
    },
    {
      "id": "CVE-2024-57726",
      "url": "https://spydr.io/cve/CVE-2024-57726",
      "published": "2025-01-15T23:15:09.520Z",
      "modified": "2026-06-17T08:13:58.677Z",
      "score": 9.9,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.66601,
      "epss_percentile": 0.9927,
      "exploited": true,
      "kev": {
        "added": "2026-04-24",
        "due": "2026-05-08",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "simple-help"
      ],
      "products": [
        "simple-help simplehelp"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role."
    },
    {
      "id": "CVE-2025-21335",
      "url": "https://spydr.io/cve/CVE-2025-21335",
      "published": "2025-01-14T18:15:58.960Z",
      "modified": "2026-09-24T13:10:00.320Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.0139,
      "epss_percentile": 0.71384,
      "exploited": true,
      "kev": {
        "added": "2025-01-14",
        "due": "2025-02-04",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows Server 2025",
        "Microsoft Windows Server 2025 (Server Core installation)"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2025-21334",
      "url": "https://spydr.io/cve/CVE-2025-21334",
      "published": "2025-01-14T18:15:58.770Z",
      "modified": "2026-06-17T08:43:07.783Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.01561,
      "epss_percentile": 0.74388,
      "exploited": true,
      "kev": {
        "added": "2025-01-14",
        "due": "2025-02-04",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows Server 2025",
        "Microsoft Windows Server 2025 (Server Core installation)"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2025-21333",
      "url": "https://spydr.io/cve/CVE-2025-21333",
      "published": "2025-01-14T18:15:58.530Z",
      "modified": "2026-06-17T08:43:07.637Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.09988,
      "epss_percentile": 0.95478,
      "exploited": true,
      "kev": {
        "added": "2025-01-14",
        "due": "2025-02-04",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows Server 2025",
        "Microsoft Windows Server 2025 (Server Core installation)"
      ],
      "cwes": [
        "CWE-122"
      ],
      "description": "Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2024-13161",
      "url": "https://spydr.io/cve/CVE-2024-13161",
      "published": "2025-01-14T18:15:26.640Z",
      "modified": "2026-06-17T07:01:20.837Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.90081,
      "epss_percentile": 0.99794,
      "exploited": true,
      "kev": {
        "added": "2025-03-10",
        "due": "2025-03-31",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Ivanti"
      ],
      "products": [
        "Ivanti Endpoint Manager"
      ],
      "cwes": [
        "CWE-36"
      ],
      "description": "Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information."
    },
    {
      "id": "CVE-2024-13160",
      "url": "https://spydr.io/cve/CVE-2024-13160",
      "published": "2025-01-14T18:15:26.447Z",
      "modified": "2026-06-17T07:01:20.707Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.91247,
      "epss_percentile": 0.99808,
      "exploited": true,
      "kev": {
        "added": "2025-03-10",
        "due": "2025-03-31",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Ivanti"
      ],
      "products": [
        "Ivanti Endpoint Manager"
      ],
      "cwes": [
        "CWE-36"
      ],
      "description": "Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information."
    },
    {
      "id": "CVE-2024-13159",
      "url": "https://spydr.io/cve/CVE-2024-13159",
      "published": "2025-01-14T18:15:26.243Z",
      "modified": "2026-06-17T07:01:20.577Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.99992,
      "epss_percentile": 0.99987,
      "exploited": true,
      "kev": {
        "added": "2025-03-10",
        "due": "2025-03-31",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Ivanti"
      ],
      "products": [
        "Ivanti Endpoint Manager"
      ],
      "cwes": [
        "CWE-36"
      ],
      "description": "Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information."
    },
    {
      "id": "CVE-2024-55591",
      "url": "https://spydr.io/cve/CVE-2024-55591",
      "published": "2025-01-14T14:15:34.450Z",
      "modified": "2026-08-05T05:16:42.380Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.94149,
      "epss_percentile": 0.99847,
      "exploited": true,
      "kev": {
        "added": "2025-01-14",
        "due": "2025-01-21",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortinet"
      ],
      "products": [
        "Fortinet FortiOS",
        "Fortinet FortiProxy"
      ],
      "cwes": [
        "CWE-288"
      ],
      "description": "An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module."
    },
    {
      "id": "CVE-2024-53704",
      "url": "https://spydr.io/cve/CVE-2024-53704",
      "published": "2025-01-09T07:15:27.203Z",
      "modified": "2026-08-04T05:16:31.367Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.95132,
      "epss_percentile": 0.99864,
      "exploited": true,
      "kev": {
        "added": "2025-02-18",
        "due": "2025-03-11",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "SonicWall"
      ],
      "products": [
        "SonicWall SonicOS"
      ],
      "cwes": [
        "CWE-287"
      ],
      "description": "An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication."
    },
    {
      "id": "CVE-2025-0282",
      "url": "https://spydr.io/cve/CVE-2025-0282",
      "published": "2025-01-08T23:15:09.763Z",
      "modified": "2026-10-01T19:17:15.743Z",
      "score": 9,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99979,
      "epss_percentile": 0.9998,
      "exploited": true,
      "kev": {
        "added": "2025-01-08",
        "due": "2025-01-15",
        "action": "Apply mitigations as set forth in the CISA instructions linked below to include conducting hunt activities, taking remediation actions if applicable, and applying updates prior to returning a device to service.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Ivanti"
      ],
      "products": [
        "Ivanti Connect Secure",
        "Ivanti Policy Secure",
        "Ivanti Neurons for ZTA gateways"
      ],
      "cwes": [
        "CWE-121",
        "CWE-787"
      ],
      "description": "A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution."
    },
    {
      "id": "CVE-2024-50603",
      "url": "https://spydr.io/cve/CVE-2024-50603",
      "published": "2025-01-08T01:15:07.127Z",
      "modified": "2026-06-17T08:04:47.600Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.98545,
      "epss_percentile": 0.99921,
      "exploited": true,
      "kev": {
        "added": "2025-01-16",
        "due": "2025-02-06",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Aviatrix"
      ],
      "products": [
        "Aviatrix Controller"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutralization of special elements used in an OS command, an unauthenticated attacker is able to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type for list_flightpath_destination_instances, or src_cloud_type for flightpath_connection_test."
    },
    {
      "id": "CVE-2024-12987",
      "url": "https://spydr.io/cve/CVE-2024-12987",
      "published": "2024-12-27T16:15:24.143Z",
      "modified": "2026-06-17T07:00:55.297Z",
      "score": 6.9,
      "severity": "medium",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "vuldb.com",
      "epss": 0.98163,
      "epss_percentile": 0.99913,
      "exploited": true,
      "kev": {
        "added": "2025-05-15",
        "due": "2025-06-05",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "DrayTek"
      ],
      "products": [
        "DrayTek Vigor2960",
        "DrayTek Vigor300B"
      ],
      "cwes": [
        "CWE-77",
        "CWE-78"
      ],
      "description": "A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an unknown function of the file /cgi-bin/mainfunction.cgi/apmcfgupload of the component Web Management Interface. The manipulation of the argument session leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.5.1.5 is able to address this issue. It is recommended to upgrade the affected component."
    },
    {
      "id": "CVE-2024-53197",
      "url": "https://spydr.io/cve/CVE-2024-53197",
      "published": "2024-12-27T14:15:27.383Z",
      "modified": "2026-06-17T08:08:33.967Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.04117,
      "epss_percentile": 0.90483,
      "exploited": true,
      "kev": {
        "added": "2025-04-09",
        "due": "2025-04-30",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Linux"
      ],
      "products": [
        "Linux"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices A bogus device can provide a bNumConfigurations value that exceeds the initial value used in usb_get_configuration for allocating dev->config. This can lead to out-of-bounds accesses later, e.g. in usb_destroy_configuration."
    },
    {
      "id": "CVE-2024-3393",
      "url": "https://spydr.io/cve/CVE-2024-3393",
      "published": "2024-12-27T10:15:17.270Z",
      "modified": "2026-06-17T07:44:11.227Z",
      "score": 8.7,
      "severity": "high",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:M/U:Amber",
      "score_source": "paloaltonetworks.com",
      "epss": 0.2912,
      "epss_percentile": 0.98121,
      "exploited": true,
      "kev": {
        "added": "2024-12-30",
        "due": "2025-01-20",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Palo Alto Networks"
      ],
      "products": [
        "Palo Alto Networks Cloud NGFW",
        "Palo Alto Networks PAN-OS"
      ],
      "cwes": [
        "CWE-754"
      ],
      "description": "A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode."
    },
    {
      "id": "CVE-2024-53150",
      "url": "https://spydr.io/cve/CVE-2024-53150",
      "published": "2024-12-24T12:15:23.117Z",
      "modified": "2026-06-17T08:08:25.567Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
      "score_source": "NVD",
      "epss": 0.01354,
      "epss_percentile": 0.70637,
      "exploited": true,
      "kev": {
        "added": "2025-04-09",
        "due": "2025-04-30",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Linux"
      ],
      "products": [
        "Linux"
      ],
      "cwes": [
        "CWE-125"
      ],
      "description": "In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix out of bounds reads when finding clock sources The current USB-audio driver code doesn't check bLength of each descriptor at traversing for clock descriptors. That is, when a device provides a bogus descriptor with a shorter bLength, the driver might hit out-of-bounds reads. For addressing it, this patch adds sanity checks to the validator functions for the clock descriptor traversal. When the descriptor length is shorter than expected, it's skipped in the loop. For the clock source and clock multiplier descriptors, we can just check bLength against the sizeof() of each descriptor type. OTOH, the clock selector descriptor of UAC2 and UAC3 has an array of bNrInPins elements and two more fields at its tail, hence those have to be checked in addition to the sizeof() check."
    },
    {
      "id": "CVE-2024-56145",
      "url": "https://spydr.io/cve/CVE-2024-56145",
      "published": "2024-12-18T21:15:08.530Z",
      "modified": "2026-06-17T08:11:45.717Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "github.com",
      "epss": 0.97405,
      "epss_percentile": 0.99898,
      "exploited": true,
      "kev": {
        "added": "2025-06-02",
        "due": "2025-06-23",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "craftcms"
      ],
      "products": [
        "craftcms cms"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Users of affected versions are affected by this vulnerability if their php.ini configuration has `register_argc_argv` enabled. For these users an unspecified remote code execution vector is present. Users are advised to update to version 3.9.14, 4.13.2, or 5.5.2. Users unable to upgrade should disable `register_argc_argv` to mitigate the issue."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
