{
  "query": {
    "exploited": "1",
    "page": "20"
  },
  "count": 20,
  "total": 1734,
  "page": 20,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T14:45:46.442Z",
    "kev": "2026-10-06T15:44:48.467Z",
    "epss": "2026-10-06T12:57:42.533Z",
    "breaches": "2026-10-06T12:45:41.825Z",
    "posts": "2026-10-06T15:45:48.663Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=20",
    "next": "https://spydr.io/threats.json?exploited=1&page=21"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2024-12686",
      "url": "https://spydr.io/cve/CVE-2024-12686",
      "published": "2024-12-18T21:15:08.020Z",
      "modified": "2026-06-17T07:00:16.763Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.137,
      "epss_percentile": 0.96391,
      "exploited": true,
      "kev": {
        "added": "2025-01-13",
        "due": "2025-02-03",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "BeyondTrust"
      ],
      "products": [
        "BeyondTrust Remote Support(RS) & Privileged Remote Access(PRA)"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative privileges to inject commands and run as a site user."
    },
    {
      "id": "CVE-2024-12356",
      "url": "https://spydr.io/cve/CVE-2024-12356",
      "published": "2024-12-17T05:15:06.413Z",
      "modified": "2026-06-17T06:59:33.887Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.87258,
      "epss_percentile": 0.99749,
      "exploited": true,
      "kev": {
        "added": "2024-12-19",
        "due": "2024-12-27",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "BeyondTrust"
      ],
      "products": [
        "BeyondTrust Remote Support",
        "BeyondTrust Privileged Remote Access"
      ],
      "cwes": [
        "CWE-77"
      ],
      "description": "A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user."
    },
    {
      "id": "CVE-2024-55956",
      "url": "https://spydr.io/cve/CVE-2024-55956",
      "published": "2024-12-13T21:15:13.767Z",
      "modified": "2026-08-05T05:16:42.863Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.93968,
      "epss_percentile": 0.99845,
      "exploited": true,
      "kev": {
        "added": "2024-12-17",
        "due": "2025-01-07",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "cleo"
      ],
      "products": [
        "cleo harmony",
        "cleo lexicom",
        "cleo vltrader"
      ],
      "cwes": [
        "CWE-77"
      ],
      "description": "In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory."
    },
    {
      "id": "CVE-2024-49138",
      "url": "https://spydr.io/cve/CVE-2024-49138",
      "published": "2024-12-12T02:04:40.307Z",
      "modified": "2026-06-17T07:59:29.057Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.26215,
      "epss_percentile": 0.97945,
      "exploited": true,
      "kev": {
        "added": "2024-12-10",
        "due": "2024-12-31",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019"
      ],
      "cwes": [
        "CWE-122"
      ],
      "description": "Windows Common Log File System Driver Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2024-55550",
      "url": "https://spydr.io/cve/CVE-2024-55550",
      "published": "2024-12-10T19:15:31.110Z",
      "modified": "2026-08-04T05:16:31.577Z",
      "score": 2.7,
      "severity": "low",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.38155,
      "epss_percentile": 0.98521,
      "exploited": true,
      "kev": {
        "added": "2025-01-07",
        "due": "2025-01-28",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "mitel"
      ],
      "products": [
        "mitel micollab"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated admin attacker to access resources that are constrained to the admin access level, and the disclosure is limited to non-sensitive system information. This vulnerability does not allow file modification or privilege escalation."
    },
    {
      "id": "CVE-2024-53104",
      "url": "https://spydr.io/cve/CVE-2024-53104",
      "published": "2024-12-02T08:15:08.687Z",
      "modified": "2026-06-17T08:08:17.170Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.03395,
      "epss_percentile": 0.88449,
      "exploited": true,
      "kev": {
        "added": "2025-02-05",
        "due": "2025-02-26",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Linux"
      ],
      "products": [
        "Linux"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format This can lead to out of bounds writes since frames of this type were not taken into account when calculating the size of the frames buffer in uvc_parse_streaming."
    },
    {
      "id": "CVE-2024-11667",
      "url": "https://spydr.io/cve/CVE-2024-11667",
      "published": "2024-11-27T10:15:04.210Z",
      "modified": "2026-08-05T05:16:40.797Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.02929,
      "epss_percentile": 0.86618,
      "exploited": true,
      "kev": {
        "added": "2024-12-03",
        "due": "2024-12-24",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Zyxel"
      ],
      "products": [
        "Zyxel ATP series firmware",
        "Zyxel USG FLEX series firmware",
        "Zyxel USG FLEX 50(W) series firmware",
        "Zyxel USG20(W)-VPN series firmware",
        "zyxel usg_flex_firmware",
        "zyxel atp_firmware",
        "zyxel usg20-vpn_firmware",
        "zyxel usg_flex_50w_firmware"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series firmware versions V5.10 through V5.38, and USG20(W)-VPN series firmware versions V5.10 through V5.38 could allow an attacker to download or upload files via a crafted URL."
    },
    {
      "id": "CVE-2024-49035",
      "url": "https://spydr.io/cve/CVE-2024-49035",
      "published": "2024-11-26T20:15:31.763Z",
      "modified": "2026-06-17T07:59:16.540Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.013,
      "epss_percentile": 0.69467,
      "exploited": true,
      "kev": {
        "added": "2025-02-25",
        "due": "2025-03-18",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Partner Center"
      ],
      "cwes": [
        "CWE-269"
      ],
      "description": "An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network."
    },
    {
      "id": "CVE-2024-11680",
      "url": "https://spydr.io/cve/CVE-2024-11680",
      "published": "2024-11-26T10:15:04.540Z",
      "modified": "2026-07-14T23:17:13.570Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.91697,
      "epss_percentile": 0.99814,
      "exploited": true,
      "kev": {
        "added": "2024-12-03",
        "due": "2024-12-24",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "ProjectSend"
      ],
      "products": [
        "ProjectSend"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of the application's configuration. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript."
    },
    {
      "id": "CVE-2024-44309",
      "url": "https://spydr.io/cve/CVE-2024-44309",
      "published": "2024-11-20T00:15:17.137Z",
      "modified": "2026-06-17T07:52:45.903Z",
      "score": 6.3,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L",
      "score_source": "NVD",
      "epss": 0.2259,
      "epss_percentile": 0.97658,
      "exploited": true,
      "kev": {
        "added": "2024-11-21",
        "due": "2024-12-12",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple Safari",
        "Apple iOS and iPadOS",
        "Apple macOS",
        "Apple visionOS",
        "apple iphone_os",
        "apple ipad_os"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 15.1.1, visionOS 2.1.1. Processing maliciously crafted web content may lead to a cross site scripting attack. Apple is aware of a report that this issue may have been actively exploited on Intel-based Mac systems."
    },
    {
      "id": "CVE-2024-44308",
      "url": "https://spydr.io/cve/CVE-2024-44308",
      "published": "2024-11-20T00:15:17.080Z",
      "modified": "2026-06-17T07:52:45.440Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.10075,
      "epss_percentile": 0.95506,
      "exploited": true,
      "kev": {
        "added": "2024-11-21",
        "due": "2024-12-12",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple Safari",
        "Apple iOS and iPadOS",
        "Apple macOS",
        "Apple visionOS",
        "apple iphone_os",
        "apple ipad_os"
      ],
      "cwes": [],
      "description": "The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 15.1.1, visionOS 2.1.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited on Intel-based Mac systems."
    },
    {
      "id": "CVE-2024-50302",
      "url": "https://spydr.io/cve/CVE-2024-50302",
      "published": "2024-11-19T02:16:32.320Z",
      "modified": "2026-06-17T08:04:10.447Z",
      "score": 5.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.00811,
      "epss_percentile": 0.55467,
      "exploited": true,
      "kev": {
        "added": "2025-03-04",
        "due": "2025-03-25",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Linux",
        "Siemens"
      ],
      "products": [
        "Linux",
        "Siemens RUGGEDCOM RST2428P",
        "Siemens SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family",
        "Siemens SCALANCE XCM-/XRM-/XCH-/XRH-300 family",
        "Siemens SIMATIC S7-1500 TM MFP - GNU/Linux subsystem"
      ],
      "cwes": [
        "CWE-908"
      ],
      "description": "In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by all kinds of drivers in various ways, let's zero-initialize it during allocation to make sure that it can't be ever used to leak kernel memory via specially-crafted report."
    },
    {
      "id": "CVE-2024-21287",
      "url": "https://spydr.io/cve/CVE-2024-21287",
      "published": "2024-11-18T22:15:05.897Z",
      "modified": "2026-06-17T07:08:56.087Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "oracle.com",
      "epss": 0.01723,
      "epss_percentile": 0.76714,
      "exploited": true,
      "kev": {
        "added": "2024-11-21",
        "due": "2024-12-12",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Oracle Corporation"
      ],
      "products": [
        "Oracle Corporation Oracle Agile PLM Framework"
      ],
      "cwes": [
        "CWE-863"
      ],
      "description": "Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software Development Kit, Process Extension). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM Framework. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM Framework accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)."
    },
    {
      "id": "CVE-2024-9474",
      "url": "https://spydr.io/cve/CVE-2024-9474",
      "published": "2024-11-18T16:15:29.780Z",
      "modified": "2026-08-04T05:16:32.247Z",
      "score": 6.9,
      "severity": "medium",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:Red",
      "score_source": "paloaltonetworks.com",
      "epss": 0.94824,
      "epss_percentile": 0.99859,
      "exploited": true,
      "kev": {
        "added": "2024-11-18",
        "due": "2024-12-09",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Additionally, the management interfaces for affected devices should not be exposed to untrusted networks, including the internet.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Palo Alto Networks"
      ],
      "products": [
        "Palo Alto Networks Cloud NGFW",
        "Palo Alto Networks PAN-OS",
        "Palo Alto Networks Prisma Access"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access are not impacted by this vulnerability."
    },
    {
      "id": "CVE-2024-0012",
      "url": "https://spydr.io/cve/CVE-2024-0012",
      "published": "2024-11-18T16:15:11.683Z",
      "modified": "2026-08-04T05:16:29.473Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:Red",
      "score_source": "paloaltonetworks.com",
      "epss": 0.99855,
      "epss_percentile": 0.99961,
      "exploited": true,
      "kev": {
        "added": "2024-11-18",
        "due": "2024-12-09",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Additionally, management interface for affected devices should not be exposed to untrusted networks, including the internet.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Palo Alto Networks"
      ],
      "products": [
        "Palo Alto Networks Cloud NGFW",
        "Palo Alto Networks PAN-OS",
        "Palo Alto Networks Prisma Access"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities like CVE-2024-9474 https://security.paloaltonetworks.com/CVE-2024-9474 . The risk of this issue is greatly reduced if you secure access to the management web interface by restricting access to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue is applicable only to PAN-OS 10.2, PAN-OS 11.0, PAN-OS 11.1, and PAN-OS 11.2 software. Cloud NGFW and Prisma Access are not impacted by this vulnerability."
    },
    {
      "id": "CVE-2024-11182",
      "url": "https://spydr.io/cve/CVE-2024-11182",
      "published": "2024-11-15T11:15:10.410Z",
      "modified": "2026-06-17T06:57:13.713Z",
      "score": 5.3,
      "severity": "medium",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "eset.com",
      "epss": 0.17591,
      "epss_percentile": 0.97066,
      "exploited": true,
      "kev": {
        "added": "2025-05-19",
        "due": "2025-06-09",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "MDaemon"
      ],
      "products": [
        "MDaemon Email Server"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "An XSS issue was discovered in MDaemon Email Server before version 24.5.1c. An attacker can send an HTML e-mail message with JavaScript in an img tag. This could allow a remote attacker to load arbitrary JavaScript code in the context of a webmail user's browser window."
    },
    {
      "id": "CVE-2024-11120",
      "url": "https://spydr.io/cve/CVE-2024-11120",
      "published": "2024-11-15T02:15:17.757Z",
      "modified": "2026-06-17T06:57:06.503Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.28386,
      "epss_percentile": 0.98076,
      "exploited": true,
      "kev": {
        "added": "2025-05-07",
        "due": "2025-05-28",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "GeoVision"
      ],
      "products": [
        "GeoVision GV-VS12",
        "GeoVision GV-VS11",
        "GeoVision GV-DSP_LPR_V3",
        "GeoVision GVLX 4 V2",
        "GeoVision GVLX 4 V3",
        "geovision gv-vs12_firmware",
        "geovision gv-vs11_firmware",
        "geovision gv-dsp_lpr_v3_firmware",
        "geovision gvlx_4_v2_firmware",
        "geovision gvlx_4_v3_firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device. Moreover, this vulnerability has already been exploited by attackers, and we have received related reports."
    },
    {
      "id": "CVE-2024-43093",
      "url": "https://spydr.io/cve/CVE-2024-43093",
      "published": "2024-11-13T18:15:21.713Z",
      "modified": "2026-06-17T07:50:25.587Z",
      "score": 7.3,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.00709,
      "epss_percentile": 0.51883,
      "exploited": true,
      "kev": {
        "added": "2024-11-07",
        "due": "2024-11-28",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Android"
      ],
      "cwes": [
        "CWE-176"
      ],
      "description": "In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicode normalization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation."
    },
    {
      "id": "CVE-2024-8069",
      "url": "https://spydr.io/cve/CVE-2024-8069",
      "published": "2024-11-12T18:15:47.603Z",
      "modified": "2026-06-17T08:21:48.323Z",
      "score": 5.1,
      "severity": "medium",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "citrix.com",
      "epss": 0.14643,
      "epss_percentile": 0.96565,
      "exploited": true,
      "kev": {
        "added": "2025-08-25",
        "due": "2025-09-15",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Citrix Session Recording"
      ],
      "products": [
        "Citrix Session Recording"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user on the same intranet as the session recording server"
    },
    {
      "id": "CVE-2024-8068",
      "url": "https://spydr.io/cve/CVE-2024-8068",
      "published": "2024-11-12T18:15:47.450Z",
      "modified": "2026-06-17T08:21:48.207Z",
      "score": 5.1,
      "severity": "medium",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "citrix.com",
      "epss": 0.03481,
      "epss_percentile": 0.88741,
      "exploited": true,
      "kev": {
        "added": "2025-08-25",
        "due": "2025-09-15",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Citrix"
      ],
      "products": [
        "Citrix Session Recording"
      ],
      "cwes": [
        "CWE-269"
      ],
      "description": "Privilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated user in the same Windows Active Directory domain as the session recording server domain"
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
