{
  "query": {
    "exploited": "1",
    "page": "21"
  },
  "count": 20,
  "total": 1734,
  "page": 21,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T16:45:50.826Z",
    "kev": "2026-10-06T16:44:50.689Z",
    "epss": "2026-10-06T12:57:42.533Z",
    "breaches": "2026-10-06T12:45:41.825Z",
    "posts": "2026-10-06T16:45:50.826Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=21",
    "next": "https://spydr.io/threats.json?exploited=1&page=22"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2024-49039",
      "url": "https://spydr.io/cve/CVE-2024-49039",
      "published": "2024-11-12T18:15:44.160Z",
      "modified": "2026-08-04T05:16:30.980Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.14179,
      "epss_percentile": 0.96484,
      "exploited": true,
      "kev": {
        "added": "2024-11-12",
        "due": "2024-12-03",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows Server 2025",
        "Microsoft Windows Server 2025 (Server Core installation)",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)"
      ],
      "cwes": [
        "CWE-287"
      ],
      "description": "Windows Task Scheduler Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2024-43451",
      "url": "https://spydr.io/cve/CVE-2024-43451",
      "published": "2024-11-12T18:15:22.483Z",
      "modified": "2026-06-17T07:51:04.273Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
      "score_source": "microsoft.com",
      "epss": 0.84108,
      "epss_percentile": 0.99689,
      "exploited": true,
      "kev": {
        "added": "2024-11-12",
        "due": "2024-12-03",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows Server 2025",
        "Microsoft Windows Server 2025 (Server Core installation)",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2008 R2 Service Pack 1"
      ],
      "cwes": [
        "CWE-73"
      ],
      "description": "NTLM Hash Disclosure Spoofing Vulnerability"
    },
    {
      "id": "CVE-2024-51567",
      "url": "https://spydr.io/cve/CVE-2024-51567",
      "published": "2024-10-29T23:15:04.307Z",
      "modified": "2026-08-04T05:16:31.190Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.86633,
      "epss_percentile": 0.99736,
      "exploited": true,
      "kev": {
        "added": "2024-11-07",
        "due": "2024-11-28",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "cyberpanel"
      ],
      "products": [
        "cyberpanel"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus by bypassing secMiddleware (which is only for a POST request) and using shell metacharacters in the statusfile property, as exploited in the wild in October 2024 by PSAUX. Versions through 2.3.6 and (unpatched) 2.3.7 are affected."
    },
    {
      "id": "CVE-2024-51378",
      "url": "https://spydr.io/cve/CVE-2024-51378",
      "published": "2024-10-29T23:15:04.083Z",
      "modified": "2026-08-05T05:16:41.870Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.94748,
      "epss_percentile": 0.99857,
      "exploited": true,
      "kev": {
        "added": "2024-12-04",
        "due": "2024-12-25",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "cyberpanel"
      ],
      "products": [
        "cyberpanel"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing secMiddleware (which is only for a POST request) and using shell metacharacters in the statusfile property, as exploited in the wild in October 2024 by PSAUX. Versions through 2.3.6 and (unpatched) 2.3.7 are affected."
    },
    {
      "id": "CVE-2024-50623",
      "url": "https://spydr.io/cve/CVE-2024-50623",
      "published": "2024-10-28T00:15:03.657Z",
      "modified": "2026-07-31T04:16:44.760Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.98607,
      "epss_percentile": 0.99922,
      "exploited": true,
      "kev": {
        "added": "2024-12-13",
        "due": "2025-01-03",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "cleo"
      ],
      "products": [
        "cleo harmomy",
        "cleo vltrader",
        "cleo lexicom"
      ],
      "cwes": [
        "CWE-434"
      ],
      "description": "In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution."
    },
    {
      "id": "CVE-2024-20481",
      "url": "https://spydr.io/cve/CVE-2024-20481",
      "published": "2024-10-23T18:15:11.737Z",
      "modified": "2026-08-11T19:40:47.230Z",
      "score": 5.8,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L",
      "score_source": "NVD",
      "epss": 0.15874,
      "epss_percentile": 0.96795,
      "exploited": true,
      "kev": {
        "added": "2024-10-24",
        "due": "2024-11-14",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco Adaptive Security Appliance (ASA) Software",
        "Cisco Firepower Threat Defense Software",
        "cisco adaptive_security_appliance_software"
      ],
      "cwes": [
        "CWE-772"
      ],
      "description": "A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of the RAVPN service. This vulnerability is due to resource exhaustion. An attacker could exploit this vulnerability by sending a large number of VPN authentication requests to an affected device. A successful exploit could allow the attacker to exhaust resources, resulting in a DoS of the RAVPN service on the affected device. Depending on the impact of the attack, a reload of the device may be required to restore the RAVPN service. Services that are not related to VPN are not affected. Cisco Talos discussed these attacks in the blog post Large-scale brute-force activity targeting VPNs, SSH services with commonly used login credentials."
    },
    {
      "id": "CVE-2024-47575",
      "url": "https://spydr.io/cve/CVE-2024-47575",
      "published": "2024-10-23T15:15:30.707Z",
      "modified": "2026-06-17T07:57:20.260Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.94766,
      "epss_percentile": 0.99858,
      "exploited": true,
      "kev": {
        "added": "2024-10-23",
        "due": "2024-11-13",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortinet"
      ],
      "products": [
        "Fortinet FortiManager"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager 6.2.0 through 6.2.12, Fortinet FortiManager Cloud 7.4.1 through 7.4.4, FortiManager Cloud 7.2.1 through 7.2.7, FortiManager Cloud 7.0.1 through 7.0.12, FortiManager Cloud 6.4.1 through 6.4.7 allows attacker to execute arbitrary code or commands via specially crafted requests."
    },
    {
      "id": "CVE-2024-41713",
      "url": "https://spydr.io/cve/CVE-2024-41713",
      "published": "2024-10-21T21:15:06.470Z",
      "modified": "2026-08-04T05:16:30.767Z",
      "score": 9.1,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "score_source": "NVD",
      "epss": 0.9811,
      "epss_percentile": 0.99911,
      "exploited": true,
      "kev": {
        "added": "2025-01-07",
        "due": "2025-01-28",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "mitel"
      ],
      "products": [
        "mitel micollab"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation. A successful exploit could allow unauthorized access, enabling the attacker to view, corrupt, or delete users' data and system configurations."
    },
    {
      "id": "CVE-2024-9537",
      "url": "https://spydr.io/cve/CVE-2024-9537",
      "published": "2024-10-18T15:15:04.170Z",
      "modified": "2026-06-17T08:24:46.673Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Red",
      "score_source": "CNA",
      "epss": 0.03826,
      "epss_percentile": 0.89766,
      "exploited": true,
      "kev": {
        "added": "2024-10-21",
        "due": "2024-11-11",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "ScienceLogic"
      ],
      "products": [
        "ScienceLogic SL1"
      ],
      "cwes": [],
      "description": "ScienceLogic SL1 (formerly EM7) is affected by an unspecified vulnerability involving an unspecified third-party component packaged with SL1. The vulnerability is addressed in SL1 versions 12.1.3+, 12.2.3+, and 12.3+. Remediations have been made available for all SL1 versions back to version lines 10.1.x, 10.2.x, 11.1.x, 11.2.x, and 11.3.x."
    },
    {
      "id": "CVE-2024-9465",
      "url": "https://spydr.io/cve/CVE-2024-9465",
      "published": "2024-10-09T17:15:20.287Z",
      "modified": "2026-06-17T08:24:37.313Z",
      "score": 9.2,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:Amber",
      "score_source": "paloaltonetworks.com",
      "epss": 0.99626,
      "epss_percentile": 0.99948,
      "exploited": true,
      "kev": {
        "added": "2024-11-14",
        "due": "2024-12-05",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Palo Alto Networks"
      ],
      "products": [
        "Palo Alto Networks Expedition"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary files on the Expedition system."
    },
    {
      "id": "CVE-2024-9463",
      "url": "https://spydr.io/cve/CVE-2024-9463",
      "published": "2024-10-09T17:15:19.973Z",
      "modified": "2026-06-17T08:24:37.050Z",
      "score": 9.9,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:Amber",
      "score_source": "paloaltonetworks.com",
      "epss": 0.98546,
      "epss_percentile": 0.99921,
      "exploited": true,
      "kev": {
        "added": "2024-11-14",
        "due": "2024-12-05",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Palo Alto Networks"
      ],
      "products": [
        "Palo Alto Networks Expedition"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls."
    },
    {
      "id": "CVE-2024-9680",
      "url": "https://spydr.io/cve/CVE-2024-9680",
      "published": "2024-10-09T13:15:12.090Z",
      "modified": "2026-08-04T05:16:32.530Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.23184,
      "epss_percentile": 0.97711,
      "exploited": true,
      "kev": {
        "added": "2024-10-15",
        "due": "2024-11-05",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Mozilla"
      ],
      "products": [
        "Mozilla Firefox",
        "Mozilla Firefox ESR",
        "Mozilla Thunderbird"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.0.2, Firefox ESR < 128.3.1, Firefox ESR < 115.16.1, Thunderbird < 131.0.1, Thunderbird < 128.3.1, and Thunderbird < 115.16.0."
    },
    {
      "id": "CVE-2024-43573",
      "url": "https://spydr.io/cve/CVE-2024-43573",
      "published": "2024-10-08T18:15:24.817Z",
      "modified": "2026-06-17T07:51:19.627Z",
      "score": 8.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
      "score_source": "NVD",
      "epss": 0.46109,
      "epss_percentile": 0.98777,
      "exploited": true,
      "kev": {
        "added": "2024-10-08",
        "due": "2024-10-29",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Windows MSHTML Platform Spoofing Vulnerability"
    },
    {
      "id": "CVE-2024-43572",
      "url": "https://spydr.io/cve/CVE-2024-43572",
      "published": "2024-10-08T18:15:24.593Z",
      "modified": "2026-06-17T07:51:19.433Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.66695,
      "epss_percentile": 0.99272,
      "exploited": true,
      "kev": {
        "added": "2024-10-08",
        "due": "2024-10-29",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)"
      ],
      "cwes": [
        "CWE-707"
      ],
      "description": "Microsoft Management Console Remote Code Execution Vulnerability"
    },
    {
      "id": "CVE-2024-43468",
      "url": "https://spydr.io/cve/CVE-2024-43468",
      "published": "2024-10-08T18:15:09.537Z",
      "modified": "2026-06-17T07:51:06.577Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.80912,
      "epss_percentile": 0.99622,
      "exploited": true,
      "kev": {
        "added": "2026-02-12",
        "due": "2026-03-05",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Configuration Manager"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "Microsoft Configuration Manager Remote Code Execution Vulnerability"
    },
    {
      "id": "CVE-2024-9380",
      "url": "https://spydr.io/cve/CVE-2024-9380",
      "published": "2024-10-08T17:15:56.970Z",
      "modified": "2026-06-17T08:24:27.317Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.59651,
      "epss_percentile": 0.99106,
      "exploited": true,
      "kev": {
        "added": "2024-10-09",
        "due": "2024-10-30",
        "action": "As Ivanti CSA 4.6.x has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line, or later, of supported solution.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Ivanti"
      ],
      "products": [
        "Ivanti CSA (Cloud Services Appliance)",
        "ivanti endpoint_manager_cloud_services_appliance"
      ],
      "cwes": [
        "CWE-77",
        "CWE-78"
      ],
      "description": "An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to obtain remote code execution."
    },
    {
      "id": "CVE-2024-9379",
      "url": "https://spydr.io/cve/CVE-2024-9379",
      "published": "2024-10-08T17:15:56.727Z",
      "modified": "2026-10-01T19:17:15.580Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.43782,
      "epss_percentile": 0.98709,
      "exploited": true,
      "kev": {
        "added": "2024-10-09",
        "due": "2024-10-30",
        "action": "As Ivanti CSA 4.6.x has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line, or later, of supported solution.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Ivanti"
      ],
      "products": [
        "Ivanti CSA (Cloud Services Appliance)"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements."
    },
    {
      "id": "CVE-2024-43047",
      "url": "https://spydr.io/cve/CVE-2024-43047",
      "published": "2024-10-07T13:15:15.257Z",
      "modified": "2026-06-17T07:50:18.910Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "qualcomm.com",
      "epss": 0.00674,
      "epss_percentile": 0.50452,
      "exploited": true,
      "kev": {
        "added": "2024-10-08",
        "due": "2024-10-29",
        "action": "Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Qualcomm, Inc.",
        "qualcomm"
      ],
      "products": [
        "Qualcomm, Inc. Snapdragon",
        "qualcomm fastconnect_6700_firmware",
        "qualcomm fastconnect_6800_firmware",
        "qualcomm fastconnect_6900_firmware",
        "qualcomm fastconnect_7800_firmware",
        "qualcomm qam8295p_firmware",
        "qualcomm qca6174a_firmware",
        "qualcomm qca6391_firmware",
        "qualcomm qca6426_firmware",
        "qualcomm qca6436_firmware",
        "qualcomm qca6574au_firmware",
        "qualcomm qca6584au_firmware",
        "qualcomm qca6595_firmware",
        "qualcomm qca6595au_firmware",
        "qualcomm qca6688aq_firmware",
        "qualcomm qca6696_firmware",
        "qualcomm qca6698aq_firmware",
        "qualcomm qcs410_firmware",
        "qualcomm qcs610_firmware",
        "qualcomm qcs6490_firmware"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Memory corruption while maintaining memory maps of HLOS memory."
    },
    {
      "id": "CVE-2024-45519",
      "url": "https://spydr.io/cve/CVE-2024-45519",
      "published": "2024-10-02T22:15:02.770Z",
      "modified": "2026-06-17T07:54:22.360Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99907,
      "epss_percentile": 0.99966,
      "exploited": true,
      "kev": {
        "added": "2024-10-03",
        "due": "2024-10-24",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "synacor"
      ],
      "products": [
        "synacor zimbra collaboration suite"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1 sometimes allows unauthenticated users to execute commands."
    },
    {
      "id": "CVE-2024-8963",
      "url": "https://spydr.io/cve/CVE-2024-8963",
      "published": "2024-09-19T18:15:10.600Z",
      "modified": "2026-06-17T08:23:38.600Z",
      "score": 9.1,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "score_source": "NVD",
      "epss": 0.98607,
      "epss_percentile": 0.99922,
      "exploited": true,
      "kev": {
        "added": "2024-09-19",
        "due": "2024-10-10",
        "action": "As Ivanti CSA has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line of supported solutions, as future vulnerabilities on the 4.6.x version of CSA are unlikely to receive security updates.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Ivanti"
      ],
      "products": [
        "Ivanti CSA (Cloud Services Appliance)",
        "ivanti endpoint_manager_cloud_services_appliance"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
